Isn't this the same company that phishes its users by asking them for their banking login and 2FA information directly in third party apps? I'm not sure if this is the sort of regulatory barrier breaking worth celebrating.
I'm sure you know well the reasons for this. It is not practical to move large amounts of money via credit card due to the fees involved.
As for your point on transaction history, you could always create a separate account specifically for these type of situations where you're passing your login. Even if they get your transaction history, it would be very limited.