The first step is disallowing EU-VAT-eligible folks from purchasing. The plugin I mention in the post is really good for that - it looks at a variety of factors including the user's billing address for their credit card, for example.
It's still totally possible that an EU citizen could be on Chinese soil, using an American's credit card, while using an Australian VPN. That means the next part of the registration will be a terms & conditions checkbox saying the GDPR doesn't apply to me. (We're working with our attorney on that language.)
At that point, if someone still registers, AND they later ask for the right to erasure, we'll still do our best to delete their data. But if they try to go to the EU and complain, we'll be on much better legal ground to say, "Look, they lied to us from the get-go, and we can prove it."
Nothing's certain - just trying to mitigate our risks as cheaply as possible.