Unless that someone posses as well the public key with the combination of private key.
It means he has full acsees to the account, create invoices, redirect payouts, refund payments etc.
But in order to achieve this that individ must have devloper skills so he can use the key.
If you don't trust the guy , I would suggest to delete/change the key