> The data includes personal names, addresses, social security numbers and everything else someone might type into a search box.
I don't think I have a similar issue with page views of one website of one session. I strip all query params and only save the hostname and path of the URL. I think it's nearly impossible to ever link that to a user. Maybe if you have very little amount of users, but then still you don't get personal info.
> Do you think this is acceptable from a privacy perspective?
But back to your point. Query params contain usually tokens, search queries, and id's. This is not so much the case for paths. I think you agree with that. But indeed, paths can have sensitive information too.
How would you prevent that data to be sent to my server?