But frankly, I don't really trust the term "personally identifiable information" unless it is qualified, because it can mean very different things to different people in different contexts[0]. For example, for one service (I believe the DNS servers) Google claims to "anonymize" IP addresses, but it turns out that they only obscure the last two or three digits, which isn't enough to conceal the identity of the individual.
For another example, you wouldn't believe some of the things that are considered protected health information when dealing with patients (ie, for HIPAA/HITECH compliance)[1].
Even if I trust a company's intentions (which I don't unless given a strong reason otherwise), trusting (a) their ability to understand what information is and isn't sensitive; and (b) guard that information both require a bit more than a vaguely worded assertion on their website.
If you collect information about where a person (or "device") has been over time, that in itself can be an incredibly identifying piece of information - all you need is one other datapoint to "lift the veil", and suddenly you know a lot of sensitive information about a particular individual.
[0] IANAL. "PII" is a legal term, and whether or not certain pieces of information qualify as PII can (and has) been litigated, so the line is ambiguous enough that a simple promise not to collect PII does little to assuage my privacy concerns.
[1] Likewise, you wouldn't believe some of the things that aren't (necessarily) considered PHI.
Is there any reason why they wouldn't just hash the IP?
They only need to see it once to extract useful information from the IP itself.
Your identity doesn't need to be attached for this information to be useful; for example, the store can say things like "gee look half our customers leave three minutes after they enter the store, so we are having a hard time converting walk-ins to sales". Or perhaps "Wow it looks like 90% of our customers come back within a week, we are doing great at getting repeat visits"
So as a retailer/third party I could correlate an IMSI/IMEI with an item that was purchased and still be in the clear so long as I do not tie the purchaser's name to it.