By including their JS, you give them full access to all of the contents of your payment page and depending on how you have configured your session cookie or depending on the browser, full access to the users session. Now in general, you can probably trust them, but what if they are compromised?
By using an iframe you make sure that they do not get access to any information on your page - much less the users session cookie.