Cloudflare Proxy, which is required for their ddos protection - and which as I recall accounts for like half of internet traffic - handles TLS termination at CF servers.

When you capture traffic at internet backbones, which the NSA does (Room 641A), you don't get to middle-man the encrypted traffic. Cloudflare gets access to unencrypted traffic, because they act as the TLS termination.

Most companies take this trade-off because "we can trust cloudflare", or "the data isn't that important, and besides it's encrypted the rest of the way anyway."