I could see the real source IPs for
all other users in last logs.
Accessing their web interfaces shouldn't be a risk, as you've already paid them and thus left a paper trail. But the point about accessing the IPs from the last ssh (or sftp) logins might be worth using a VPN for. If another user is able to get them law enforcement could too (not that it's likely).
SFTP / SSH encryption in transit is perfectly safe.
The seed box itself will probably have logs on it that you accessed it from your home IP
The seed box hosting provider might have logs that you're connecting to them from your home.
Your ISP can see that you accessed a box on a hosting provider with an encrypted protocol.
As long as you're not hosting anything so serious that a state agency will come in raid the hosting provider break into the box and grab the content and logs, you really have nothing to worry about.
Yes.
While there is no end to paranoia, I would call a VPN over sftp quite useless.
Unless, of course, the seedbox itself needs a VPN to be reached in the first place.