What your internet provider sees of your browsing
All your traffic passes through them
Your internet provider is the intermediary for every connection you make. That is not an opinion or a suspicion: it is how the network works. The interesting question is not whether they can see something, but what exactly.
What they can see
The domains you visit. Even when the content is encrypted with HTTPS, the server name usually travels readable when the connection opens. Your carrier can record that you entered a specific site, and at what time.
Your DNS queries, if you use theirs by default, which is the norm. That is, every domain your device asks how to reach.
How much and when. Data volume, times of day, connection duration. Quite a lot about your habits can be inferred from that.
Your approximate location, from the infrastructure you connect through.
What they cannot see
The contents of pages encrypted with HTTPS. They do not read your messages or see what you type into a form.
The specific pages within a site. They know you entered a domain; not which article you read inside it.
It is an important distinction: they know which building you entered, not which room you were in.
What changes with a VPN
With a VPN active, your carrier sees a single encrypted connection to the VPN server. They stop seeing the list of domains you visit.
But that does not make the problem disappear: it moves it. Now the VPN provider is the one in that position.
So the relevant question when choosing a VPN is not "does it hide me from my carrier?" — they all do — but "do I trust this provider more than my carrier, and why?".
How to judge that trust
Look at whether they explain exactly what they log and for how long, in detail. Be sceptical of an unqualified "zero logs": if a service has a website, that website has access logs.
Look at how they are funded. If it is free and unexplained, the question answers itself.
Our answer to both is in what we log and why it is free. Read them critically, which is how these things should be read.