Purely a guess but I think they only allow for numbers because it's a phone company. If they intend for people to enter their password/pin on their mobile phone then limiting it to only digits that you can type from any phone is understandable. Now I'm not saying it's a good idea but at least there is some sense to it.
In no particular order my usual gripes with passwords and auth in general are:
* Disabling clipboard copy/paste (because now I can't use my password manager)
* Length limitations (anything less than 32 characters is a a limitation)
* Requiring punctuation or "special characters" (they're annoying and don't add real security ... just use a longer password)
* Lack of two-factor (preferably TOTP)
The password limit is really the scariest one. Short passwords are much easier to crack. Also, I have a sinking feeling that every site that says a password must be a specific max length is storing it in plaintext. Otherwise why the heck would it matter what the length is?