> I suppose they have my DNS lookups, but it's trivial to change DNS to a company you trust
That won't solve it, there's still what's called "passive DNS". With passive DNS someone between you and the internet (in this case your ISP) simply tags and stores all DNS packets it sees before forwarding them to wherever they're supposed to go. From that they can determine which domains you are resolving even if you aren't using their resolver. They can also block DNS requests, and even send you their own responses. That last part doesn't matter as much as you'd think: they can't just redirect you to an Ad server because they wouldn't be able to authenticate the SSL connection.
I should also add that this DNS snooping has legitimate and ethical uses. A big reason to do this is to deal with malware. Often malware uses certain domain names as their command and control server. If this malware has spread far and wide and could affect a lot of your customers, you can black hole the domain name so that, if you have the malware and it tries to resolve mycommandandcontrolserver.biz, the ISP intercepts the request and send back an NXDOMAIN, or have it resolve to 0.0.0.0, or resolve it to a particular server that simply closes every connection it gets so you can figure out which customers are affected and contact them.
They can also get the hostname for https connections the initial SSL connection sends the hostname in plaintext (called SNI). But getting that requires reconstructing the TCP stream for connections in real time, and that's just not very practical at ISP scale.