just_somebody Once installed, sandboxed google play knows about all installed apps within a profile and can potentially communicate with them. It has no access to hardware identifiers but an unique advertising ID is created and since Google can communicate with other apps, it can be shared.
If you don't want an advertising ID, don't install sandboxed services and store or wait until GrapheneOS development team fully understand how exactly apps talks to eatch other.
I'm not an expert but communication scopes could potentially stop an app from working (in particularly apps from Google)