> how customers navigate their store [a]isles.
Sure, physical stores can do that in certain way, certainly they cannot reverse pickpocket GPS trackers into our pockets or stalk us around the city. You can ask your customers how they found about your store but they can lie or simply not answer. Cameras in the store? Fine. Cameras in the store bathroom? Not ok.
It is a legitimate interest to understand where your customers are coming from and this can be done without cookies in an anonymous fashion. Similarly, you can understand what people purchase together in an anonymous fashion. Cookies and PII aren't needed for any of this.
Cookies and PII are only necessary when you are trying to surreptitiously correlate people's purchase pattern with something that you shouldn't legitimately know like their sexuality or any given aspect of their identity.
> Lastly - the EU and it's laws don't matter. What are they going to do about non-compliant foreign websites? Nothing.
Rightly so. But if your third party processor is operating in the EU they will hold them liable for processing the data on EU citizens you send them without consent. That is between the EU and your provider.