> Unencrypted web traffic?
I don't know if you're aware, but basically all sites on the internet use something called SSL these days. However, SSL is useless if you use a VPN that also provide DNS servers (which most do) - because the provider could listen in on all of your traffic by hijacking the handshake, DNS and traffic to and from any target server - making it much easier to create a user profile, because you're authenticated to the VPN.
Also, third party cookies are blocked in the mainline browsers by default, making VPNs even more useless.
Most if not all of the ISPs also use dynamic IPs, making it unlikely to be cross-site-tracked based on IP sources.