HTTP/1.1 200 OK
Server: nginx/1.17.3
Content-Type: text/html; charset=UTF-8
Transfer-Encoding: chunked
Connection: keep-alive
Vary: Accept-Encoding
Cache-Control: no-cache, private
Date: Fri, 17 Feb 2023 17:28:25 GMT
Content-Security-Policy: default-src 'self' https://hotelcard.com/ https://*.hotelcard.com/ https://www.google-analytics.com/ https://firebaseinstallations.googleapis.com/ https://fcmregistrations.googleapis.com/ https://firebase.googleapis.com/ https://stats.g.doubleclick.net/ https://bid.g.doubleclick.net/ https://api.trustyou.com/ https://s7.addthis.com/ https://hotelcard.ch/ https://*.hotelcard.ch/ https://www.awin1.com/ https://the.sciencebehindecommerce.com/ https://www.paypal.com/ https://player.vimeo.com/ https://www.youtube.com/ https://youtu.be/ https://api-public.addthis.com/ https://www.getback.ch/ https://apps.elfsight.com/ https://api.instacloud.io/ https://m.youtube.com/ https://wchat.eu.freshchat.com/ https://500159408622426.eu.webpush.freshchat.com/ https://tagmanager.google.com/ https://unbounce.com/ https://landing.hotelcard.com/ https://ads.google.com/ https://www.hotjar.com/ https://www.facebook.com/ https://m.addthis.com/ https://vars.hotjar.com/ https://in.hotjar.com/ https://ws7.hotjar.com/ http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io wss://*.hotjar.com https://e-payment.postfinance.ch/ https://epayment.postfinance.ch/ https://maps.googleapis.com/ https://secure.pointspay.com/ https://*.pointspay.com/ https://ion.hotelcard.de/ https://hooks.stripe.com https://*.google-analytics.com; font-src 'self' https://fonts.gstatic.com/ https://use.fontawesome.com/ https://fonts.gstatic.com/ http://script.hotjar.com https://script.hotjar.com http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://cdnjs.cloudflare.com/; img-src 'self' data: https: https://hotelcard-files.ams3.cdn.digitaloceanspaces.com/ https://hotelcard-files.ams3.digitaloceanspaces.com/ https://maps.gstatic.com/ https://hotelcard-stage-files.fra1.digitaloceanspaces.com/ https://www.facebook.com/ https://www.google.com/ http://www.awin1.com/ http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io https://script.hotjar.com http://script.hotjar.com; script-src 'self' 'unsafe-inline' 'unsafe-eval' https://use.fontawesome.com/ https://www.gstatic.com/ https://maps.googleapis.com/ https://www.googletagmanager.com/ https://s3.amazonaws.com/ http://s3.amazonaws.com/ https://www.google-analytics.com/ https://www.googleadservices.com/ http://www.googleadservices.com/ https://connect.facebook.net/ https://googleads.g.doubleclick.net/ https://cdnjs.cloudflare.com/ https://cdn.jsdelivr.net/ https://s7.addthis.com/ https://z.moatads.com/ https://v1.addthisedge.com/ https://m.addthis.com/ https://hotelcard.us12.list-manage.com/ https://www.dwin1.com/ https://code.jquery.com/ https://maxcdn.bootstrapcdn.com/ https://static.profity.ch/ https://www.getback.ch/ https://www.awin1.com/ https://the.sciencebehindecommerce.com/ https://www.google.com/ https://static.getback.ch/ https://apps.elfsight.com/ https://static.elfsight.com/ https://wchat.eu.freshchat.com/ https://assetscdn-wchat.eu.freshchat.com/ https://snap.licdn.com/ http://static.hotjar.com https://static.hotjar.com/ https://script.hotjar.com/ http://www.awin1.com/ https://ws7.hotjar.com/ http://*.hotjar.com https://*.hotjar.com http://*.hotjar.io https://*.hotjar.io http://*.addthis.com/ https://ion.hotelcard.de/ https://*.hotelcard.de/; style-src 'self' 'unsafe-inline' https://fonts.googleapis.com/ https://use.fontawesome.com/ https://cdnjs.cloudflare.com/ https://maxcdn.bootstrapcdn.com/ https://www.getback.ch/ https://static.getback.ch/ https://wchat.eu.freshchat.com/
Permissions-Policy: accelerometer=(self), autoplay=(self), camera=(self), cross-origin-isolated=(self), document-domain=*, encrypted-media=(self), fullscreen=(self), geolocation=(self), gyroscope=(self), magnetometer=(self), microphone=(self), midi=(self), payment=(self), picture-in-picture=*, publickey-credentials-get=(self), screen-wake-lock=(self), sync-xhr=*, usb=(self), xr-spatial-tracking=(self)
Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
X-Download-Options: noopen
X-Permitted-Cross-Domain-Policies: none
X-XSS-Protection: 1; mode=block
Referrer-Policy: no-referrer
Set-Cookie: XSRF-TOKEN=eyJpdiI6ImpwcG80WXJmRU01cVZGM2pVSXpaaWc9PSIsInZhbHVlIjoicEJmWFhScGU2NFpiVUJYZDhVdXhGMG8vNFkzWnd2QkxteGNtbDl3eUxQMFBvTGNKZ1hVeG8vejVjaUpJTjBTTnBqYVBlTG5IazRZUTFnYkhialFWQ2dBQzJabGdibHZwbjVrTkcxeWNYT0VkcE5MaEJRdmdVYXBxTjF5VUdySzEiLCJtYWMiOiI4Zjc0NTgyNzNjM2JiMzBlYmY1MjVjMjlhM2UzNjM1MTgyMGIwM2ZhODVkYWJiYjUzNDU3YzFkOTZmZTAwNGRjIiwidGFnIjoiIn0%3D; expires=Sat, 18-Feb-2023 11:04:25 GMT; Max-Age=63359; path=/; samesite=lax
Set-Cookie: hotelcard_session=eyJpdiI6IlFwNk5mVkhJTXM5M0VrbFdjTEw0K3c9PSIsInZhbHVlIjoiVnFjVnBoWGZwRVExVHJXYnFZZlVOZkU1MDlDSWpRMHFuNXBWdDF6TEJ2ckxSSEFobXNkb1pVY1FLTHdBekdlM3RFWHoxaDJrelh1Z1MwRGJia2RWa2lLd3Y3Q1VBbHJ0RDlZd0VjREdoWGZBam1hbEVST1VsZ3ZEaHVZK1NGUXUiLCJtYWMiOiJlMTIxZTdjNmFlMTEzN2RiZTNiMWZkMmI3M2QwYTUxM2RkZTYxZTY2MDY0OGFkZWU5N2MwZjFmZjU2ZDFkNjNiIiwidGFnIjoiIn0%3D; expires=Sat, 18-Feb-2023 11:04:25 GMT; Max-Age=63359; path=/; httponly; samesite=lax
Set-Cookie: locale=de; expires=Fri, 17-Mar-2023 17:28:24 GMT; Max-Age=2419198; path=/; httponly; samesite=lax
Set-Cookie: currency=eyJpdiI6InA1aVNsK2d6MDNPc0gwTWI0QTgyU3c9PSIsInZhbHVlIjoiMzdiVXNvVjJBQi9TK3l1SENiYi8xYkVmMVh3ekxhUEZXa3hxQXQ3dDVNQkVERjNPdk1qaU9uZm0yTUliU29CbyIsIm1hYyI6IjE4YjJhNDNiMDVkYWMwZWQ4MGFkODI1YzJiM2RlNGQ5ZTAxNGMzNjNjNmU3MTZmNmM5NDViYWExMThhZGI2YjAiLCJ0YWciOiIifQ%3D%3D; expires=Fri, 17-Mar-2023 17:28:24 GMT; Max-Age=2419198; path=/; httponly; samesite=lax
Content-Security-Policy: frame-ancestors https://admin.hotelcard.com 'self';
X-XSS-Protection: 1; mode=block
X-Content-Type-Options: nosniff
|