Disclaimer: This is not legal advice.
Yes, the lack of assets and revenue would make it difficult to collect. Exposure could include a staff member wanting to visit an EU country, the company trying to hire an EU-based remote contractor, or trying to get credit in the US.
That said, the reasoning is simpler: even if there's literally zero interaction with or exposure to the EU, by the time a complaint gets to litigation, the company's approach to GDPR has already failed. erely being party to a case in any court (let alone losing one) isn't a trivial matter -- it means at least consulting an attorney and thinking through the implications (like perhaps not being able to obtain an EU visa). A GDPR strategy which gets to that point, and relies on the inability to collect a judgment, has failed.
Facebook - really, FANG and a handful of other name-brand, global, consumer-facing companies - differ from most businesses in 2 ways:
1. They expect litigation, complaints, and article 17 erasure requests. There's no way to avoid it, just plan around it and minimize the impact. Their goal isn't no impact, it's no catastrophic impact.
2. They have teams of attorneys analyzing the risk and benefit of every decision. If they've decided (not) to do something, it's because they've accepted that the risks are worth the benefits, not necessarily because they think it's risk-free. Even most mid-market businesses don't have that luxury.
Note also that my original comment said that experts debate whether user-submitted location is sufficient. I explicitly didn't and don't claim that there's any certainty. There's no case law at all right now, so anyone who claims certainty about edge cases is making stuff up.
What is close to certain is that IP-based geocoding (ie, what this vendor provides) doesn't eliminate anywhere near all visitors from the EU, and thus doesn't eliminate the need to consider GDPR. Perhaps they decide to also add a user-submitted location dropdown to their signup form and accept the risks I just described, or decide to do nothing else and accept the risk of litigation from EU visitors who the geocoding doesn't identify. My core point is that the geocoding service pitches "Just block EU IPs and you're done," and that's not the case at all.
I think we're past the point where HN comments are adding value, so this will be my last comment in this thread.