Any merchant that accepts credit card payments must be PCI compliant. Even if cardholder data never touches the merchant's servers, the merchant still falls under the scope of SAQ A[1].
1: https://www.pcisecuritystandards.org/documents/pci_saq_a_v2....