The only real "possibly" here could be if shopper or server are infected with malicious program which can see the information before it's wrapped in https. However, if a person is contaminated with this kind of software program, they're going to have usage of the data, regardless of the you use to transport it.@EJP, the domain is visible due to SNI