I'm not CM, but...
I see, you are using a CAPTCHA. I'm not sure if it was there from the beginning.
1. What's the purpose of it?
Stopping abuse, of course.

i.e people spamming sessions as a DDoS measure.
2. Is it generated through some third party service?
It's just an image, most likely fully generated on their server (and it doesn't point to any external website; check it yourself: right click -> open image in a new tab -> check url).
3. If yes, which one? Do not they get to know your customer's data as well?
Answer seems obvious here.

4. How about using HCAPTCHA instead of it?
Answer also seems obvious. Of course it's not a good idea to implement a third party script on their website, specially due to their nature.