So you would rather take your business to somewhere that got hacked, didn't pay the ransom, and got customer data leaked?
The customer data is already leaked, unless your threat model somehow includes trusting threat actors to keep said data confidential in perpetuity.
If you believe the hackers didn’t keep a copy of the data, you’re the target market.
Both of them got hacked so... yes.
Theoretically, if it happened before and the ransom wasn’t paid, there’s both an incentive by the service to improve their security practices and a disincentive on the hackers to target that business.
Yes, particularly if they are transparent about it.