I’ve worked on payment systems. It is very hard to federate unless something like Stripe is used for actual payment.
Credit card companies simply won’t interface with you unless you prove their data is safe. It isn’t a process that scales well.
Brick and mortar companies get around this by having payment terminals which are insanely locked down. (Which is also why those terminals mostly suck)
I see this the same as a company asking for a SSN. I didn’t pick it, it is really hard to change without physical/mental pain, and is spoofable anyway.
Based on those criteria… I’m not sure why I care about sharing it. I wouldn’t solely use it for something I’m securing myself, but if some company wants too, I don’t really take issue.