Note TrustWave, a widely trusted certificate authority, has recently explicitly acknowledged selling devices with subordinate root certificates that allow them to spoof certs for any domain that they want in order to allow companies to snoop on their employees.
http://blog.spiderlabs.com/2012/02/clarifying-the-trustwave-...If they are willing to sell these to private organizations, who's to say that one of the many certificate authorities have not sold such devices or certificates to repressive governments?
SSL is basically a joke at this point. Because it requires you to trust every single certificate authority for every single domain, it basically means that you are only protected against the average script kiddie, not a dedicated attacker. There have been plenty of CAs compromised, who continued to issue MD5 signed certificates well after it was broken, who are within the control of authoritarian governments, or who are willing to sell subordinate root certs for the purpose of snooping to any company who is willing to pay enough.
And that's not to mention that even if the information is properly protected in transit, putting this information on your servers makes you that much more vulnerable to attackers who may want access to this information, the government of the country in which it is hosted, legal process, or any number of other threats. Even if they had properly secured the information in transit, and SSL were secure, it still vastly increases your customers exposure to upload this information to your servers.