This website is a small, local company. They have a newsletter signup page so they do collect user info. Quite likely they are not GDPR compliant (e.g. take longer than 30d to delete records, don't have a process for answering data requests etc). It is reasonable for them not to want to invest in getting the legal advise to know whether they are compliant or process improvements to become compliant, as there is no ROI on that.
I love GDPR, but it's understandable for folks with no connection to the EU to just nope-out.
I’m still not clear why US companies with no business units in Europe feel the need to make any changes at all to be in compliance with a law that has no jurisdiction over them, but agree that Geofencing is a cheaper solution than asking a lawyer.