When it calls https to hand the info over, it encrypts it.
The only "non-secure" portion is the fact someone can see the empty login screen that they presented to you.