I'm not quite ready to +1 the idea though. It's intriguing, but seems to open a user up to abuse. Unsolicited messages (email, SMS, IM, DM, Facebook, etc.) are a popular way of phishing (tricking individuals into giving away private information). One tip security pros repeat over and over is not to click on unsolicited links.
While you say customers will only provide payment information to a company they trust, what is to keep a crook from impersonating a trusted vendor and tricking a customer into paying them instead of the actual company?
I'm all for convenience when done safely, and perhaps your business model accounts for this - I'm just curious what you have done to prevent SMS-based payments from turning into a source of fraud.