It is completely the user's choice to put sandboxed google play in a private space or secondary user profile. It is completely the user's choice to put sandboxed google play services in the owner profile and not use multiple profiles at all. It is completely the user's choice to source apps from outside Google Play.