This doesn't look to be a Pi-hole issue:
Pi-hole only deals with your local DNS traffic.
It is receiving DNS requests and forwards allowed ones to its configured upstreams.
Interception and forceful redirection of outbound DNS requests to your VPN provider's DNS server would be something that your VPN gateway or VPN client software could be expected to do.
You should consider consulting your VPN provider's documentation and support.
That said, your debug log indicates that your Eero(?) routing equipment is advertising its own IPv6 ULA as local DNS server, e.g.:
*** [ DIAGNOSING ]: Discovering active DHCP servers (takes 6 seconds)
Scanning all your interfaces for DHCP servers and IPv6 routers
(…)
* Received 80 bytes from fe80::<redacted>d @ wlp130s0f0
Hop limit: 64
(…)
Recursive DNS server 1/1: fd<redacted>::1
DNS server lifetime:600 sec
This would allow your IPv6 clients to by-pass Pi-hole via fd<redacted>::1.
This may or may not contribute to your DNS leak observation, e.g. if your VPN wouldn't be configured to handle IPv6 traffic.
Regardless, you'd have to find a way to configure your router to stop advertising its own IPv6 as DNS server, or to advertise your Pi-hole host machine's IPv6.
You'd have to consult your router's documentation sources on further details for its IPv6 configuration options.
If your router doesn't support configuring IPv6 DNS, you could consider disabling IPv6 altogether, provided you'd not depend on IPv6 for reasons.
If your router doesn't support that either, your IPv6-capable clients will always be able to bypass Pi-hole via IPv6.
You could then try to mitigate this, by setting Pi-hole as the only upstream of your router, provided your router supports it.
But note that you won't be able to attribute DNS requests to original individual IPv6 clients in such a configuration.