The webpage might be http, but the Stripe Javascript library connects to Stripe's servers over https.
The website never sees your card number and your card number and info is never transmitted over a non-encrypted connection.
Which is ironic.
Stripe explains that TLS is required in their docs: https://stripe.com/help/ssl
You can make live transactions just fine from a regular HTTP page - whether that's a good idea or not is another issue, but making Stripe payments from an HTTPS payment page is not required from an API point of view.
The page that sends the POST request should also be verifiable as owned by the domain, otherwise I could inject a different "payment system" library, that looked like stripe to the user (unless they analyzed the traffic), but actually sends me the CC details.
From https://stripe.com/help/ssl
> Do I need to use SSL/TLS on my payment pages?
> Yes, for a couple of reasons:
> - It's more secure. In particular, it significantly reduces your risk of being exposed to a man-in-the-middle attack.
> - Users correctly feel more comfortable sharing their payment information on pages visibly served over SSL. Your conversion rate is likely to be higher if your pages are served over SSL/TLS, too.
Payment seems to be done using Stripe Javascript SDK, which makes all the connections using HTTPS.