They are not periodically running credit checks. If they were, then people with active credit monitoring would be notified, even for "soft" checks.
Basically, the seller never stores (and ideally never even sees) the buyers' card numbers. Instead, the card numbers are stored by the PSP, which then issues seller-specific tokens associated to each card. The seller can then store the tokens, and use them to process any payments to their verified accounts. If the tokens are ever leaked or stolen they are useless to an attacker, as these tokens can only be used with that specific PSP to perform payments in favour of the seller for whom they were issued in the first place.
If that's the case, it would be an incremental improvement if the credit agencies implemented some tokenization scheme, sort of like credit card gateways do.
Not that anyone should trust the credit agencies either, but you'd still be removing unnecessary points of potential compromise.
Going to collections over $50 is stupid.