Software typically obtains BSSIDs from your mobile OS’s wi-fi frameworks.
The BSSID looks like a MAC address, and in many but not all cases, a given AP’s wireless network BSSID is within a byte or two of its actual wi-if radio MAC.
Google and Apple maintain their own massive geolocation databases of BSSIDs, signal strength, and latitude/longitude.
It is way before HTTP even happens. This data is collected while you are driving around, walking down the street, etc.
If you want coarse location to work but don't want Google to know it, try microG with a non-Google location provider (I use Apple and Mozilla and it's pretty good).
> Google's location service improves location accuracy > by using Wi-Fi, mobile networks, and sensors to help > estimate your location. Google may collect location > data periodically and use this data in an anonymous > way to improve location accuracy and location-based > services. > > Turning this off will result in your device only using GPS > for location. This may impact the accuracy of location > used by apps such as Maps and Find My Device.
Based on that description, that should turn off the data collection, although it can also make GPS fixes take longer, and there may well be other apps collecting this data as well.
I believe they also track and log other Wifi networks that you arnt even connected to.
I'm sure they gather all sort of other metrics from any sensors and signals they can access.
I tried some quick packet sniffing browsing Google and did not see my MAC transmitted—as I’d expect (bc like you said, ARP not thing at this layer) also research on “MAC included in http metadata” turns up no results…
If you have any more info on this I’d love to learn more—as I’m puzzled to know why this would happen?