Earlier quoted context omitted.
It doesn't matter who it's handled by, the fact is that credit card numbers are being transferred over regular, non-encrypted HTTP.
Actually, it does matter. The webpage might be http, but the Stripe Javascript library connects to Stripe's servers over https . The website never sees your card number and your card number and info is never transmitted over a non-encrypted connection.
Which is ironic.