This is a classic case of the perfect vs the good. The question is not whether SHA1 is “acceptable”, but whether it is better than the alternative, which is plain text for users that cannot do SHA256. It’s graceful degradation.
The number quoted of $70K to crack SHA1 indicates that it is non-trivial to hack. Which means adversaries could break the encryption, but could only afford to attack a small number of people. Which means that SHA1 is effective for a large majority.