Specifically if you hash the password client side then the hash fundamentally becomes the password, and having that sit plaintext in logs is identical to the pre-hash password since both can re-played to authenticate.
I believe this is still a respected/secure version of what you describe:
https://en.wikipedia.org/wiki/Secure_Remote_Password_protoco...
(Provided either you, or all the other services using this scheme, are sensible enough to salt with a string unique to their website such as a domain name)
As they're incredibly opaque about what they're doing, it's hard to tell whether they're part of the "get it wrong" crowd, but being incredibly opaque about what they're doing doesn't bode well.
Otherwise its vulnerable to replay attacks
Anyway, it's been a long time ago, and if I had to do it again today, i would rather not roll my own.