This. The only real issue is that the teams implementing this decided not to do a data security assessment and are violating PCI-DSS and similar by recording things that are supposed to be stored securely or not at all (ex. CCV).
Also, as I recall, banks legitimately "track" user interactions as a means of fraud detection.