They may still be compliant and storing your credit card responsibly, I would assume they used Stripe or similar and they're only sending the last 4 digits back over standard http. If they're allowing you to add a new card, then there's an issue.
replies(1):