If you think through what you've just stated logically, you'll find that if you'd just allowed the site to set up the passkey on the local Windows 11 PC for convenience (for example, if your phone wasn't handy or working for whatever reason atm), then you could have later also set up the passkey capability on your smartphone and used the QR code from your alredy registered PC to create the same exact passkey (actually private key( on your phone as well, giving you the best of both worlds using the PC for access at home without requiring the phone, and then the smartphone when needing to access the same website from any other device with which the phone's Bluetooth could confirm that you're locate close-by when attempting to use its private key to validate your identity.
That's the beauty of the passkey system, since it makes this combination of events possible, which also has the advantage of creating an inherent backup of the passkey on multiple devices to ensure that losing one of those devices doesn't also lose the only copy of the passkey.
Fortunately, you should still be able to create this same situation in reverse by using the camera on your laptop to read a QR code from the phone in order to move the passkey in the opposite direction, assuming the laptop has a camera that supports reading QR codes.
Here's an article that describes how passkeys work from the FIDO Alliance, which created and supports the standards it's built on, and includes many industry players like Microsoft, Apple, Google and others who are of course required in order for passkeys to work across these multiple platforms and websites.
How Passkeys Work | Passkey Central
And here's a paragraph from that article titled; 'Passkeys are private by design', that shows why they don't themselves allow tracking you, though most like Google who commonly do this have other ways that circumvent this using things like fingerprinting or simply the fact that most people don't choose to disable location tracking on their phones for other reasons.
"A unique passkey is created for each domain and account. So there is no way for multiple online services to collaborate to track the user. The device unlock (using biometric or PIN) stays local. The online service only sees public keys and signatures from the user's device. For a person to use the private key, the password manager uses an API provided by the operating system to directly leverage the familiar, and private-by-design, device unlock that device operating systems have already been shipping for many years now."
Rob