GrapheneOS has Google Play installed on the phone, but it's in its own sandbox. That means it sends real telemetry to google, but is limited to what it can see from within the sandbox
Its important to note that it isn't bundled and installed by default though. And that if you use privacy friendly apps, they are unlikely to talk to Google Play via IPC. And you can also restrict such communication by putting them in separate profiles.
CalyxOS doesn't support Google Play at all. It has Aurora Store and you can install migroG to get access to apps from Google Play. The only interaction with Google is push notifications, which are also optional.
You might find this explanation of the downsides of the approach useful https://discuss.grapheneos.org/d/4290-sandboxed-microg/11
So problem is that it runs privileged, doesn't have the most secure reimplementation, and for some functionality (not only push notifications like you mentioned) still talks to Google, but in this case does via a component that, as mentioned, runs privileged, thus increasing privacy and security issues. Google Play dependent apps also often bundle Google Play libraries, the explanation about just cutting out the middle man is quite interesting. Especially noting that middle man is more secure. Same holds for the store. Play Store does better verification of app installs, including verifying their metadata, compared to Aurora. And Play has better and more reliable auto updating of apps, which is important to get security patches.
This means some apps won't work. Sound like it's mostly banking apps that break.
That's true. Compatibility with apps will be higher with sandboxed Google Play due to it using the real unalerted Google Play but just forced in the app sandbox. GrapheneOS also has more exploit mitigations and if those give compatibility issues they can turned off on an app by app basis. Banking apps more often implement misguided or mismarketed libraries for "security" and anti-tampering. One of those libraries is Play Integrity API, which is sometimes impossible to work around, and will give issues on both OSes given that they are uncertified.
