If, I assume the data is being sent back to their servers over HTTPS .. wouldn't that make this process of encrypting the "data" superfluous and have no impact on the overall security - or did I miss something?
I'm not defending this mess just curious.