Payment services like Google and Amazon take a small cut of the transaction, but they allow customers to skip all the formfields simply by entering a password.
In his personal blog Grossman has described how a malicious website could create form text fields, probably invisibly, for the contact info it wanted to extract from a Safari user.