I was going to ask something similar. Especially US companies seems rather fond of storing credit card information, but I never seem it done in Denmark, regardless of the size of the company. The most common solution is to let your payment processor deal with those sorts of things, you just have a token, which can only be used to deposit money into your account. So even if it's stolen or leaked, you can transfer the money back, they can't be transferred to a third party.
Why on earth you'd want to deal with credit card information and the attacks it attracts is beyond me. It's not like you're locked to the your provider, the tokens can be transferred... Not easily, but it can be done.
And no, companies would never pay Stripes asking price. You can negotiate much much lower rates with companies like Valitor/Rapyd or certain banks.