Update to this. It's been about a month since I moved everything over, no issues or bans (yet). Below is what I ended up doing:
I was able to move my wife's save data over to the switch 2, and I took extra care to ONLY transfer save data for games we own. On both the clean sysnand of the hacked switch, and on the switch 2, I took the time to insert the cartridge for every game we own, and let the system create a save data for it. I verified this by checking the save data in the game information itself. Once that was done, I made sure wifi was disabled, then rebooted the sysnand on the switch, used hekate to boot "Cfw" on the sysnand, and ONLY launched JKSV via applet mode (via album), then proceeded to inject the saves for all the games we own that she has files for. Once done, I powered off the system, removed the SD card just in case, then powered on normally, and re-enabled wifi, verified the linked nintendo account was still good by going into the eshop, as well as verify the saves of some games. Once ready, I then used the save data transfer on both systems and brought the switch 2 near it like it asked.
For Animal Crossing, used JKSV to inject both the system and BCAT save data, powered down and removed the sd card, re-enabled wifi after powering the system back up, went into the eshop and downloaded the animal crossing save transfer tool on both systems, followed the guide to transfer the data over. Then on the switch 2 It just asked me to link a user for the island.
I'm really paranoid that somehow they will detect something and eventually ban the system, but as already mentioned, ive only transferred data for owned physical games or purchased digital games, and the saves themselves are not modified in anyway. Pretty confident the sysnand is indeed clean, as no installed games on the emunand show up when booting the sysnand. Its been over 24 hours, so fingers crossed.