This is going to be informational, as we had a good conversation over this area on Craft Slack. And good fun trying to get around the idiotic StackExchange 'subjective' monitor to publish it here -- couldn't imagine what this wanted.
Why would you want to avoid PCI compliance on your own server? Because it's a bank-level task to get and maintain it.
See the conversation linked in the answer below, thank you.