Earlier quoted context omitted.
> I can't remember every giving explicit consent for this and AFAIK under GDPR just covering this in a Privacy Policy is not enough. I don't believe Deliveroo is obligated to tell you who they send such information to. They are however obligated to tell you that they gather such information and, should they share it with a third party, ensure that said third party is GDPR compliant and sign a data processing agreemen…
Doesn't GDPR require explicit cosent[0] for collection of sensitive private information? This is what many website has implemented as popups with "I accept" or "Manage Settings" options. I don't remember going through such a flow with Deliveroo and if I did I would have disabled the "marketing" category for sure. 0: https://www.i-scoop.eu/gdpr/explicit-consent/
To add to what detaro was saying; even if explicit consent were required for sharing your location data, Deliveroo most likely got it; they after all need it to know where your order is going to go. When such functionality is core to the app, an opt-out is not necessary.
What they might not have gotten, or at least not clearly, is your consent to send that data to a third party, explicitly and exclusively for marketing purposes. I don't know how this would play out.
Realistically, GDPR and its enforcers err on the side of caution (you need good justification to gather the data and share it, including consent and a reason to gather it in the first place). So if you care about this and wish to see it corrected, as I said an email to their dpo@ will likely go a long way. In case it doesn't, your national enforcement agency may be interested. Extremely-accurate location data is pretty creepy, especially if they get it very often and doubly so if they store it for a long time.
The #1 thing I would look at here is what they actually need it for. They may need it for security reasons (eg. anti-fraud measures) and happen to be storing it in Braze which is probably okay if Braze respects GDPR and Deliveroo signed a DPA with them (you'd be surprised the amount of companies storing security data in GA).
But you wouldn't have a very hard time making a case that they're using this for marketing purposes and are gathering an unreasonable amount of accuracy. So now the question is, do you care about this enough to follow up on it? :)