I'm also wary of an API that tries to be all things to all people--as evidenced by the shoehorning in of shipping and delivery options.
EDIT:
Also, we see stuff like so:
> The PaymentRequest API does not directly support encryption of data fields. Individual payment methods may choose to include support for encrypted data but it is not mandatory that all payment methods support this.
What problem is this solving again? How does this make developers' lives easier than existing solutions? I'm kinda thinking it doesn't.