I probably didn't help in describing the idea clearly, but who do you mean by "
which you host"?
My thought process was that it would work like this:
Merchant - Hosts a a payment form, but it POSTs to the service's server basically <form method="post" action="https ://someservice.com">
Service - Receives the POST and forwards it on to Auth.NET, Paypal Pro, or whoever the Merchant is using to process transactions. The user is redirected back to merchantwebsite.com with appropriate response data.
Are you saying the merchant website would still need to be PCI compliant or just the Service's?
I definitely understand that the service would have to be PCI compliant. But it seems like it'd be a valuable service for a number of small e-commerce providers to essentially outsource online PCI compliance with minimal downside.
EDIT: While I haven't used them, my understanding is that Braintree offers pretty much exactly this service, except that they require that they provide your merchant account and act as your payment processor.