They are basically MITM (man-in-the-middle) attack all the traffic that passes through their servers. Most Cloudflare defenders will tell you it's not technically MITM as the site operators gives them permission to do that, but the end result is the same.
Even though sites are encrypted, they hold the decryption key, so they can see all traffic in plain text.