So you don't need to know anything about credit cards for someone to enter it into an app? I don't get the take (is it bad sarcasm?)
To your last question about bucket policies, clearly you just need to scope it down: arn:aws:sts::*:assumed-role/trustme*/*
(indeed that first wildcard means any account)
To be fair, for the vast majority of cases, no you don't.
It is extremely rare for companies to roll their own payment processing anymore, or even handle PCI scope at all.