GDPR would be fine if they had a limits for small businesses. As written, startup founders don't have the resources to comply, so they often end up blocking all of Europe.
Not sure about the "hosted on US soil" part, if you are a US company, the data gets transfered anyway when you view it.