Ok understood, I got mixed up with terminology.
To clarify with proposed hub priority - Site-to-Site VPN settings for spokes on dashboard will look like this
1. DC-Hub (no default route selected)
2. HQ-Hub (default route selected)
I understand difference between split tunnel and full tunnel, however given what's written in doco regarding behavior when default route is selected and also explicit 0.0.0.0/0 route is configured on HQ-Hub.
My interpretation is that public traffic from spokes will route through via HQ-Hub despite DC-Hub being higher in priority.
--------------------------------------------------------------------------------------------------------------------------------------------
Default Route
When configuring Hubs for a Spoke, there is an option to select a hub as being a Default route. If this option is selected, then that hub will be configured as a default route for the Spoke (0.0.0.0/0). Any traffic that is not sent to a configured VPN peer network, static route or local network will be sent to the default route. Multiple hubs can be selected as default routes. Hubs marked as default routes take priority in descending order (first priority at the top).
https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-Site_VPN_Settings