I have said it a million times not, DO NOT RELY ON JAVASCRIPT FOR IMPORTANT INFORMATION.
Not to mention the fact that any 13 year old kid could come in and wreck havok.
To submit to both paypal AND your site's purchase processing system:
Paypal supports a post-back or data return ability that lets your script know if the payment succeeded, amount paid, ect. Use cURL or fsock to submit the form data to paypal, get the response, and then take the appropriate action based on the result.
Not only does this mean the you can control every aspect of the payment process, and they will never leave your site or see a paypal logo, it also means that every payment will come from your server host/ip and you may use that as a security feature. ( IE: Did this payment come from my server? No?! Cancel Transaction. )