If the company was storing as much data as you are claiming, play store would never allow them to go live in the first place. Second, if you’ve linked you gmail account to some app there’s an option in google’s privacy setting to terminate the link between the apps. Go to data and privacy —> thirdparty apps and services –> select the app –> delete all connections which you have with the app.
Now simply go to security, log out all your active sessions and then reset your password.
Now enable 2 factor authentication like mobile no or authenticator app.
Also make sure no mobile enable other than your phone in google prompts.