The number of webmasters who wanted me to set up ssl to 'secure' their site, while the backend emailed cc info in the clear to the orders dept is larger than I have digits, even the extra adolecent joke ones.
To be honest credit cards are a terrible system in terms of security. Everything to make a charge is on the card and people freely give it out to different websites.
They _assume_ card numbers will get stolen all the time and invest in identifying suspicious behavior. And all behavior is 100% auditable all the time. Security isn't just about authentication/authorization. I wish more websites assumed passwords might get phished and thought through how to protect users in that case.
My credit card numbers are one of my pieces of private information I feel _least_ apprehensive about sharing.