This is an interesting topic. I've struggled a bit with separate profiles because they are not as convenient as having a single profile. I ultimately ended up using Shelter in my owner profile. Within Shelter, I've installed Google Play Services and have a handful of apps that either need it, or are privacy invasive, and I don't want them to have IPC with apps in my "main" profile. This has been working flawlessly. For apps that need to provide notifications, I let them run in the background. I freeze all other apps so they're effectively disabled until I need them. As soon as the app is dismissed or I lock my screen, the app(s) is(are) frozen automatically.
I'll also say the line for the "average piece of shit guy with average data" moves closer and closer to the "center" everyday in the USA. Average piece of shit guy today becomes public enemy #1 tomorrow. My 2¢.