Maybe they won't upload the list of my installed apps (which can leak information like religion or medical issues), maybe they won't track my location through the entire hotel (or everywhere), maybe they won't snoop on my pictures... but maybe they also will, and I don't like maybe.
Almost certainly I'll have to agree to lengthy ToS that will then be used as justification to inundate me with spam.
The Android permission model is particularly messed up because it changes every few SDK target versions, so it's hard to build a mental model what exactly you're allowing. Many apps that had a built-in photo-taking capability required storage access and wouldn't work without. Any app using bluetooth had to request and be granted location access (because Bluetooth could be used to track location... so any app acting as a key automatically also got to track you via GPS on top of that, and even if the app maker didn't want to they had to request the permission for Bluetooth to work).
I've seen too many companies pushing their apps aggressively and with massive rewards. They're clearly getting something out of it, and probably not something I want to give them. If you're very, very lucky, the main goal is only to make them more "sticky" (make it easier to use them over someone else next time), but that's the thing - I don't want past service providers to stick to me.