Adaire:
The personal details that are being given to you by the customer when you are using Papal are no more sensitive than what can be found in the phone book. SSL slows down your cart considerably. The default setting in most browsers, is to not have anything cache from secure pages. The encryption causes everything in the browser to run like cold honey. The big problem is that your average user doesn't understand this (well apparently not many tech support people either) so you have to point this out in a friendly and short paragraph. Don't get suckered into an SSL cert if you don't have to. My host charges $25.00 just to install one if I already have it.
While there's some truth to your comments, look at it from another angle... security is your friend when it comes to e-commerce. If customers don't feel secure, they won't buy. If you aren't protecting data and you end up with any sort of lawsuit, you don't have much to stand on. Gosh, an SSL certificate doesn't have to be expensive, nor does the installation or hosting related to it. By all means, don't pay more than you have to, but don't skimp on security just to save a couple bucks. Besides, you can write it off as an expense anyway. It'll save you in the long run .... and, depending on what you're selling and who you're selling to, it'll MAKE you more sales, which theoretically should MAKE you more money...
By the way, check out the laws in your geographic region and the regions where your customers come from, to determine whether there are legal requirements for protecting customer data. And, state ALL the details of your privacy policy ON your site. If you are protecting customer data, say so. If you're not, say so. Or at least get your attorney to write up the politically correct wording. (That'll cost a ton more than an SSL certificate, by the way.)