I think the main reason for this is market competition. There used to be a bunch of companies selling smartphones 10~15 years ago, but now there are only a handful overall. Most companies don't have an incentive to make it easy, if at all possible, to unlock the bootloader to install an OS that they cannot control.
Your privacy depends a great deal on how you use your phone. If you still send emails to Gmail accounts, search for information online through Google search, your GPS is wired to Google maps, and sign in to websites and other services using your Google account, then there's very little point in moving away from Android.
The same is true for your computer, by the way, Zorin OS by itself won't make you any more private if you still use software like Microsoft Edge or Google Chrome, or use services from companies that gather and sell your data for profit, like Discord or Reddit.
As with most things, moderation is key and if you are concerned about privacy I would recommend taking it one step at the time. No need to make drastic changes to your lifestyle overnight. Moving away from Windows and into Linux is already a great first step, so kudos to you.
Unfortunately things aren't looking so bright in that regard. Companies are focused on selling you a new device every few years, and as I mentioned above there's very little competition these days and thus no incentive to make the use of alternative OS any easier to the consumer.
My recommendation to you since you will definitely need to buy a new device, is to go for Google's Pixel. Ironic as it may seem at first, Google has put a lot of effort into making the Pixel phone secure and has a ton of security features built-in. In addition, it's the only hardware manufacturer (that I'm aware of) that guarantees updates for at least 5 years. Other components (camera, screen, battery life, etc) are also quite decent.
GrapheneOS is a security and privacy focused Android ROM that only runs on Pixel phones because all of this. You will have to install it yourself but it's your best bet if you need to buy a new phone and care about privacy. This is the best combination as far as privacy goes, and with the least amount and quality of life compromises.
Now, Pixels aren't the cheapest either. Other options do exist that are cheaper but you'd have to check if those devices are supported by LineageOS, DivestOS, CalixOS or whatever other ROM you choose. But to be perfectly honest, I see no point in not getting a Pixel even if you didn't care about privacy at all:
For one, Android is controlled by Google already anyway so you might as well get a phone that has the best integration with Google services and receives updates much sooner. Updates that you are guaranteed to receive for at least 5 years which is considerably longer than what any other companies promise.
All in all, it still has excellent components that can compete with other high-end smartphones. While Pixel's aren't the cheapest, the smartphone market is so consolidated (due to the lack of competition that I mentioned) that prices are rising anyway. This makes the Pixel a more viable and cost efficient option anyway.
And, of course, is the only device that supports the best security- and privacy-focused Android ROM that you can possibly install if you choose to do so.