My 2 cents then we'll get on with the issue at hand
I'm not supportive of people who resist spending money on their business. the phrase 'Penny wise and pound foolish' is what comes to mind. I know a good amount of businesses who use paypal vs doing a traditional merchant account. thats fine and good... However if he carelessly put's client info on the web he could be in trouble of some sort.
With that said you're going to need to go with option number 1. How you keep their information secure and private may be a whole other issue. We're hear to help, so your going to look at having meta tags which tell google and other SE's to not index those pages. How you keep the location of those pages from unwanted eye's will need more work. See if you can have passworded directories with registerfly without any added cost. Hopefully they won't limit that amount.