Google Play's Data Safety Form

Every Play app completes the Data safety form and links a privacy policy. In Google's terms, data is collected when it leaves the device, whether your code or a library's sends it, and shared when it goes to a third party. Data used only on the device isn't declared, nor is data processed ephemerally, held in memory just long enough to answer one request. Start from the permissions in the release manifest, which show what the app could reach:

Listing the permissions in BookNest's release APKJSX
APK=android/app/build/outputs/apk/release/app-release.apk
aapt2 dump permissions $APK | grep -c "uses-permission"
aapt2 dump permissions $APK | grep -o "android\.permission\.[A-Z_]*" | cut -d. -f3 | sort -u \
  | paste -sd' ' | fold -s -w 90
Output
34
ACCESS_COARSE_LOCATION ACCESS_FINE_LOCATION ACCESS_NETWORK_STATE ACCESS_WIFI_STATE CAMERA
FOREGROUND_SERVICE FOREGROUND_SERVICE_MEDIA_PLAYBACK INTERNET MODIFY_AUDIO_SETTINGS
POST_NOTIFICATIONS READ_APP_BADGE RECEIVE_BOOT_COMPLETED USE_BIOMETRIC USE_FINGERPRINT
VIBRATE WAKE_LOCK

Most of the 34 come from libraries' manifests, 16 of them launcher-badge permissions for other vendors' home screens. Then trace what each feature sends:

BookNest's features mapped to the Data safety form
Feature (section) Data sent off the device Form entry
Checkout (Forms and Validation) Name, email, street address Personal info: collected, for app functionality
Orders, sign-in (3.18, Authentication) Books ordered, account name Purchase history; user IDs
Push (Push Notifications) Expo 6,418 push token Device or other IDs
Cover upload (Camera and Media) A photo the reader picks Photos and videos: collected, optional
Store locator (Maps and Location) Nothing: distances are computed on the device Not declared

The location permissions serve the store locator, but BookNest sorts the shops on the device, so its own code collects no location; the Google Maps 1 SDK behind react-native-maps 15,999 has its own Data safety guidance, which you must read too. The form also asks about encryption in transit: the release allows plain HTTP to 10.0.2.2 only because the Detox 12,028 plugin's network_security_config.xml permits it, so a store build points EXPO_PUBLIC_API_URL at an HTTPS server and drops that plugin.