HTTP/1.1 301 Moved Permanently
Retry-After: 0
Location: https://max.co.nz/
Content-Length: 0
Accept-Ranges: bytes
Date: Wed, 01 Jun 2022 00:59:26 GMT
Connection: close
X-Served-By: cache-lga21975-LGA
X-Cache: HIT
X-Cache-Hits: 0
X-Timer: S1654045167.950152,VS0,VE4
Vary:
Strict-Transport-Security: max-age=31557600
HTTP/2 302
cache-control: max-age=0, must-revalidate, no-cache, no-store
content-security-policy-report-only: font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.typekit.net *.trustedshops.com *.trustpilot.com *.googleapis.com cdn1.stamped.io stamped.io https://mcstaging.max.co.nz/ https://fonts.gstatic.com/ https://fonts.gstatic.com https://js.intercomcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.nosto.com *.nos.to *.paymentexpress.com *.windcave.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google.com *.doubleclick.net *.facebook.com *.nosto.com *.nos.to *.laybuy.com *.addthis.com www.xtento.com *.paymentexpress.com *.windcave.com https://plumrocket.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://accounts.google.com *.weltpixel.com https://vars.hotjar.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://static.afterpay.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net https://a.klaviyo.com *.nosto.com *.nos.to *.cloudflare.com https://cdn.klarna.com *.gstatic.com *.paypal.com *.afterpay.com https://s.ytimg.com *.usercentrics.eu *.trustpilot.com *.googleapis.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pushalert.co cdn1.stamped.io stamped.io https://scontent.cdninstagram.com/ https://integration-assets.laybuy.com/ http://mcstaging.max.co.nz/ https://usage.trackjs.com/usage.gif https://downloads.intercomcdn.com https://static.intercomassets.com https://pixel.quantserve.com https://www.google.com.ua https://c.clarity.ms https://c.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://api.addressfinder.io https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com polyfill.io *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net https://static.klaviyo.com https://fast.a.klaviyo.com *.avada.io *.nosto.com *.nos.to *.cloudflare.com foursixty.com *.trustedshops.com *.usercentrics.eu *.trustpilot.com *.googleapis.com *.intercomcdn.com *.intercom.io *.addthis.com *.addthisedge.com *.moatads.com www.xtento.com cdn.xtento.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://accounts.google.com *.pushalert.co cdn1.stamped.io stamped.io *.maxmind.com https://foursixty.com https://static.hotjar.com https://cdn.trackjs.com/ https://script.hotjar.com https://js-agent.newrelic.com https://widget.intercom.io https://bam.nr-data.net https://js.intercomcdn.com https://static-tracking.klaviyo.com https://www.clarity.ms https://secure.quantserve.com rules.quantcount.com *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.addressfinder.io static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.googleapis.com *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.nosto.com *.nos.to *.cloudflare.com *.typekit.net foursixty.com *.trustedshops.com *.usercentrics.eu *.trustpilot.com unsafe-inline https://accounts.google.com cdn1.stamped.io stamped.io https://foursixty.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.addressfinder.io static.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.algolia.net *.algolianet.com *.google-analytics.com *.facebook.com *.facebook.net *.klaviyo.com https://fast.a.klaviyo.com *.nosto.com *.nos.to *.cloudflare.com foursixty.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.afterpay.com *.intercom.io *.google.com *.googleapis.com *.algolianet.net *.cardinalcommerce.com *.braintreegateway.com *.braintree-api.com stamped.io cdn1.stamped.io *.mmapiws.com *.trackjs.com *.hotjar.com *.hotjar.io/* api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://accounts.google.com *.pushalert.co https://foursixty.com wss://nexus-websocket-a.intercom.io https://capture.trackjs.com/ https://ws19.hotjar.com https://in.hotjar.com https://api-iam.intercom.io https://s07ch2n2bo-2.algolianet.com/ https://bam.nr-data.net wss://ws16.hotjar.com/api/v2/client/ws https://ws16.hotjar.com wss://ws19.hotjar.com/api/v2/client/ws https://ws8.hotjar.com/api/v2/sites/2434348/recordings/content https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://vc.hotjar.io/sessions/ https://stats.g.doubleclick.net *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
content-type: text/html; charset=UTF-8
expires: Tue, 01 Jun 2021 00:59:27 GMT
location: https://www.max.co.nz/
pragma: no-cache
set-cookie: PHPSESSID=6b5fc4708de63aa6b38675506990ddab; expires=Wed, 01-Jun-2022 01:59:27 GMT; Max-Age=3600; path=/; domain=max.co.nz; secure; HttpOnly; SameSite=Lax
set-cookie: X-Magento-Vary=c58cc7336841735bf5ef13185766282824a9d073; expires=Wed, 01-Jun-2022 01:59:27 GMT; Max-Age=3600; path=/; secure; HttpOnly; SameSite=Lax
x-content-type-options: nosniff
x-debug-info: eyJyZXRyaWVzIjowfQ==
x-frame-options: SAMEORIGIN
x-platform-server: i-02b616f1bfe53c7e0
x-platform-server: i-02b616f1bfe53c7e0
x-request-id: 00-16f45950e47d22c6f9deb7a563e2aa13-128698e0c1c18785-00
x-xss-protection: 1; mode=block
accept-ranges: bytes
date: Wed, 01 Jun 2022 00:59:27 GMT
x-served-by: cache-akl10328-AKL, cache-lga21921-LGA
x-cache: MISS, MISS
x-cache-hits: 0, 0
vary: Accept-Encoding,Cookie
strict-transport-security: max-age=31557600
content-length: 0
HTTP/2 200
content-security-policy-report-only: font-src *.gstatic.com 'self' data: *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.cloudflare.com *.typekit.net *.trustedshops.com *.trustpilot.com *.googleapis.com cdn1.stamped.io stamped.io https://mcstaging.max.co.nz/ https://fonts.gstatic.com/ https://fonts.gstatic.com https://js.intercomcdn.com data: 'self' 'unsafe-inline'; form-action secure.authorize.net test.authorize.net pilot-payflowlink.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.nosto.com *.nos.to *.paymentexpress.com *.windcave.com https://plumrocket.com 'self' 'unsafe-inline'; frame-ancestors 'self'; frame-src fast.amc.demdex.net *.adobe.com secure.authorize.net test.authorize.net www.paypal.com www.sandbox.paypal.com pilot-payflowlink.paypal.com player.vimeo.com *.youtube.com https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.google.com *.doubleclick.net *.facebook.com *.nosto.com *.nos.to *.laybuy.com *.addthis.com www.xtento.com *.paymentexpress.com *.windcave.com https://plumrocket.com c.paypal.com checkout.paypal.com assets.braintreegateway.com pay.google.com *.cardinalcommerce.com https://accounts.google.com *.weltpixel.com https://vars.hotjar.com 'self' 'unsafe-inline'; img-src assets.adobedtm.com amcglobal.sc.omtrdc.net dpm.demdex.net cm.everesttech.net *.adobe.com widgets.magentocommerce.com data: www.googleadservices.com www.google-analytics.com www.paypalobjects.com t.paypal.com *.ftcdn.net *.behance.net www.paypal.com fpdbs.paypal.com fpdbs.sandbox.paypal.com *.vimeocdn.com i.ytimg.com https://static.afterpay.com 'self' data: *.google.com *.google.bg *.facebook.com *.facebook.net *.doubleclick.net https://a.klaviyo.com *.nosto.com *.nos.to *.cloudflare.com https://cdn.klarna.com *.gstatic.com *.paypal.com *.afterpay.com https://s.ytimg.com *.usercentrics.eu *.trustpilot.com *.googleapis.com www.xtento.com cdn.xtento.com www.sandbox.paypal.com b.stats.paypal.com dub.stats.paypal.com assets.braintreegateway.com c.paypal.com checkout.paypal.com *.pushalert.co cdn1.stamped.io stamped.io https://scontent.cdninstagram.com/ https://integration-assets.laybuy.com/ http://mcstaging.max.co.nz/ https://usage.trackjs.com/usage.gif https://downloads.intercomcdn.com https://static.intercomassets.com https://pixel.quantserve.com https://www.google.com.ua https://c.clarity.ms https://c.bing.com data: 'self' 'unsafe-inline'; script-src assets.adobedtm.com *.adobe.com secure.authorize.net test.authorize.net www.googleadservices.com www.google-analytics.com www.paypalobjects.com js.braintreegateway.com www.paypal.com www.sandbox.paypal.com t.paypal.com s.ytimg.com www.googleapis.com vimeo.com www.vimeo.com *.vimeocdn.com https://www.gstatic.com/recaptcha/ https://www.google.com/recaptcha/ www.googletagmanager.com geostag.cardinalcommerce.com 1eafstag.cardinalcommerce.com geoapi.cardinalcommerce.com 1eafapi.cardinalcommerce.com songbird.cardinalcommerce.com includestest.ccdc02.com https://api.addressfinder.io https://portal.sandbox.afterpay.com https://portal.afterpay.com https://static.afterpay.com https://js.sandbox.afterpay.com https://js.afterpay.com polyfill.io *.google.com *.google.bg *.googletagmanager.com *.facebook.com *.facebook.net *.doubleclick.net https://static.klaviyo.com https://fast.a.klaviyo.com *.avada.io *.nosto.com *.nos.to *.cloudflare.com foursixty.com *.trustedshops.com *.usercentrics.eu *.trustpilot.com *.googleapis.com *.intercomcdn.com *.intercom.io *.addthis.com *.addthisedge.com *.moatads.com www.xtento.com cdn.xtento.com assets.braintreegateway.com c.paypal.com pay.google.com api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://accounts.google.com *.pushalert.co cdn1.stamped.io stamped.io *.maxmind.com https://foursixty.com https://static.hotjar.com https://cdn.trackjs.com/ https://script.hotjar.com https://js-agent.newrelic.com https://widget.intercom.io https://bam.nr-data.net https://js.intercomcdn.com https://static-tracking.klaviyo.com https://www.clarity.ms https://secure.quantserve.com rules.quantcount.com *.clarity.ms 'self' 'unsafe-inline' 'unsafe-eval'; style-src *.adobe.com https://api.addressfinder.io static.afterpay.com/ js.sandbox.afterpay.com js.afterpay.com *.googleapis.com *.doubleclick.net *.facebook.com *.fontawesome.com maxcdn.bootstrapcdn.com *.nosto.com *.nos.to *.cloudflare.com *.typekit.net foursixty.com *.trustedshops.com *.usercentrics.eu *.trustpilot.com unsafe-inline https://accounts.google.com cdn1.stamped.io stamped.io https://foursixty.com https://fonts.googleapis.com 'self' 'unsafe-inline'; object-src 'self' 'unsafe-inline'; media-src *.adobe.com cdn1.stamped.io stamped.io 'self' 'unsafe-inline'; manifest-src 'self' 'unsafe-inline'; connect-src dpm.demdex.net amcglobal.sc.omtrdc.net www.google-analytics.com www.sandbox.paypal.com www.paypalobjects.com www.paypal.com geostag.cardinalcommerce.com geo.cardinalcommerce.com 1eafstag.cardinalcommerce.com 1eaf.cardinalcommerce.com centinelapistag.cardinalcommerce.com centinelapi.cardinalcommerce.com *.addressfinder.io static.afterpay.com js.sandbox.afterpay.com js.afterpay.com *.algolia.net *.algolianet.com *.google-analytics.com *.facebook.com *.facebook.net *.klaviyo.com https://fast.a.klaviyo.com *.nosto.com *.nos.to *.cloudflare.com foursixty.com *.paypal.com *.sandbox.paypal.com *.paypalobjects.com *.afterpay.com *.intercom.io *.google.com *.googleapis.com *.algolianet.net *.cardinalcommerce.com *.braintreegateway.com *.braintree-api.com stamped.io cdn1.stamped.io *.mmapiws.com *.trackjs.com *.hotjar.com *.hotjar.io/* api.braintreegateway.com api.sandbox.braintreegateway.com client-analytics.braintreegateway.com client-analytics.sandbox.braintreegateway.com https://accounts.google.com *.pushalert.co https://foursixty.com wss://nexus-websocket-a.intercom.io https://capture.trackjs.com/ https://ws19.hotjar.com https://in.hotjar.com https://api-iam.intercom.io https://s07ch2n2bo-2.algolianet.com/ https://bam.nr-data.net wss://ws16.hotjar.com/api/v2/client/ws https://ws16.hotjar.com wss://ws19.hotjar.com/api/v2/client/ws https://ws8.hotjar.com/api/v2/sites/2434348/recordings/content https://a.klaviyo.com/ https://telemetrics.klaviyo.com/ https://vc.hotjar.io/sessions/ https://stats.g.doubleclick.net *.clarity.ms 'self' 'unsafe-inline'; child-src assets.braintreegateway.com c.paypal.com http: https: blob: 'self' 'unsafe-inline'; default-src 'self' 'unsafe-inline' 'unsafe-eval'; base-uri 'self' 'unsafe-inline';
content-type: text/html; charset=UTF-8
expires: Wed, 01 Jun 2022 12:48:45 GMT
pragma: cache
x-content-type-options: nosniff
x-debug-info: eyJyZXRyaWVzIjowfQ==
x-esi: 1
x-frame-options: SAMEORIGIN
x-platform-server: i-02b616f1bfe53c7e0
x-platform-server: i-02b616f1bfe53c7e0
x-request-id: 00-16f43171380d1dafcd66db605b8b0b24-d6f13e40b7ed77ef-00
x-xss-protection: 1; mode=block
date: Wed, 01 Jun 2022 00:59:28 GMT
age: 43842
x-served-by: cache-akl10320-AKL, cache-lga21928-LGA
x-cache: HIT, MISS
x-cache-hits: 1, 0
cache-control: no-store, no-cache, must-revalidate, max-age=0
vary: Accept-Encoding,Cookie
strict-transport-security: max-age=31557600
|