The set of small businesses in the US that don't use Stripe, Square, Braintree, etc to run their payments is so minuscule as to be insignificant.And once again, there is a world outside the US, and some of its customs will be different to those you are familiar with. I've had more than one small shop or food place I buy stuff from clearly demonstrate that after a previous phone order paid by card, they'd just written down all the details and still had them on file, including the CVC.
I'm not sure what your argument is here. Debit cards fall under PCI-DSS compliance. We're talking about payment cards, not just credit cards.
Just for perspective, a rough calculation suggests that less than 25% of the money I have spent in the past 5 years was paid by card, whether credit or debit. The majority of the payments I make by far are via the UK bank faster payments system, standing orders, Direct Debit, etc. I don't think this is particularly unusual in the UK, or a lot of other places that have similar methods available.
First of all, this is false on its face because you would have to know their PIN.
And yet again, there is life outside the US, and the rest of the world doesn't necessarily work the same way you do. For example, you might like to look up contactless payments, which have been ubiquitous in places like the UK for many years.
Second of all, the threat model of physical theft of a credit card is extremely narrow.
And what about the person who had an opportunity to handle your card for a few seconds and record the numbers?
What about the problems inherent in those contactless payments I mentioned, where someone can literally walk past you in the street and use a device to scan your card details if they pass close to you?
What about the online businesses using the modern card payment services, but whose sites get hacked (or just cloned on a similar-looking domain) so that at the payment form/script stage it's not really Stripe or PayPal you're giving your card details to?
Apparently your threat model is excluding quite a lot of the potential threats.
It requires tinfoil-hat levels of paranoia to think that merely being within earshot of an Android phone renders you susceptible to surveillance. Unless Google has information on you, personally, it's extremely difficult to correlate background audio noise to you personally, and that would only be possible if you actually went and used Google's services.
No, it isn't. Voiceprints are a unique biometric marker, and the technology to isolate individual voices in a recording with a high degree of accuracy has existed for a long time.
You're potentially subject to surveillance any time you're within audible range of a device that monitors for trigger words (typically with considerably less than 100% accuracy) and then uploads the following audio to the mothership.
Or just because someone had an app that accessed the microphone, covertly or otherwise, and then uploaded the audio for whatever reason; take your pick.
Directly analogous arguments, other than the voice activation triggers, apply to photos taken on phones and subsequently uploaded to cloud storage or shared on social media as well.
And if you're this paranoid about indirect exposure to Google, you can send PGP encrypted e-mails, even to people that use G-mail. You have the tools!
Unfortunately, the person I'm sending to usually won't, and I have no way to determine whether they are using Google to handle their email anyway.