· 8 min read · Wwwebtech Team

Who Owns Your Website? Ask Before You Sign

Your domain, hosting, code, content and analytics can each sit in someone else's account. Here is exactly what to ask for, in writing, before you pay.

A website is not one thing you own. It is five or six separate things, held in five or six separate accounts, and there is nothing stopping a different person from controlling each one. Most owners discover this at the worst possible moment — when they want to change agency, when a developer stops replying, or when the domain quietly expires because the renewal notice went to an email address they have never seen.

None of this requires bad faith. A small studio registers the domain on your behalf because it is faster than walking you through a registrar signup. Three years later that studio has shut, and the person who knew the password has moved to Dubai. The result is the same as if someone had held your site hostage deliberately.

So the useful question before you sign anything is not "how much" or "how long". It is: at the end of this, whose name is on what?

The five things that can be owned separately

Think of your web presence as a stack. Each layer can belong to a different party.

1. The domain name

This is the single most important item and the one most often mishandled. A domain has a registrant — the legal holder — recorded with the registry. For .in domains that is NIXI, the National Internet Exchange of India; for .com it is Verisign. You can look up who is listed using any RDAP or WHOIS lookup, though privacy protection may mask the details.

What matters is whose account the domain sits in at the registrar (GoDaddy, BigRock, Namecheap, Hostinger and so on) and whose email receives the renewal notice. If both belong to your agency, you do not control your own address on the internet. You control the content at the end of it, which is a much weaker position.

2. DNS — the phone book

DNS, short for Domain Name System, is the record that says "this domain points at that server, and email for this domain goes to that mailbox". It can live at your registrar, at your host, or at a service like Cloudflare. It is often the layer nobody documents, and it is the layer that breaks email when a site is moved badly. Know where your DNS is managed and have login access to it.

3. Hosting and the files

Hosting is where the site actually runs. The questions are: is the hosting account in your business name and billed to your card, or is your site one folder inside a reseller account holding forty other clients? Can you get SFTP or cPanel access? Can you download a full backup — the files and the database — without asking permission?

A reseller arrangement is not automatically wrong. It is often cheaper and better managed than what a non-technical owner would buy alone. But you should know that is the arrangement, and you should have a written route to your own copy of everything.

4. The code and the licences

If your site is WordPress, the core software is licensed under the GPL and cannot be withheld from you. Premium themes and plugins are different: many are sold as annual licences tied to the buyer's account. If your agency bought Elementor Pro or a booking plugin under their developer licence, your updates stop the day the relationship ends. That is not theft, it is how the licence works — but you need to know which plugins are on your site and whose licence keys are activating them.

Custom code raises a sharper question. Unless your contract assigns copyright or grants you a perpetual licence, the developer may own what they wrote. For most small business sites this never becomes a dispute. It becomes one the moment you want a different firm to modify the code.

5. Content, and the accounts around the site

Photography is the usual trap. A photographer or agency may have licensed images to you for use on the website only, not for print, not for hoardings, not forever. Ask. Stock images bought under an agency's subscription can carry the same restriction.

Then the surrounding accounts, which people forget entirely:

  • Google Analytics — historical data does not travel. If the property sits in the agency's account and they remove your access, three years of traffic history is gone as far as you are concerned.
  • Google Search Console — verified ownership should sit with your Google account, not only theirs.
  • Google Business Profile — this has a primary owner. Managers can edit but cannot transfer. If an agency is the primary owner of the listing that brings you walk-in customers, that is a real risk.
  • Business email — a Google Workspace or Microsoft 365 tenant registered by someone else is worse than a website problem. That is your correspondence.
  • Payment gateway and SSL — Razorpay or PayU merchant accounts must be in your entity's name regardless, but check who holds the dashboard login.

What to ask for in writing

You do not need a lawyer to draft this. A one-page annexure to the proposal is enough, and any honest firm will sign it without argument. Ask for these clauses:

  1. Registrant clause. "All domain names are registered in the name of [your company], in an account under [your email], to which the client has administrative login at all times." If the agency manages renewals, that is fine — management is not ownership.
  2. Asset schedule. A list, updated at handover, of every account created for the project: registrar, host, CDN, analytics, email, any third-party service. With the URL, the username, and who holds the password manager entry.
  3. Exit clause. "On termination, and provided invoices are settled, the agency will supply a full site backup (files and database), transfer domain authorisation codes, and transfer ownership of all connected accounts within X working days." Name the number of days. Vagueness here is where disputes live.
  4. Licence clause. Either copyright in bespoke code and design transfers to you on final payment, or you receive a perpetual, transferable licence to use and modify it. Both are acceptable. Neither being stated is not.
  5. Content clause. Photography and copy usage rights spelled out — web only, or all media, and for how long.

One practical note on domains: ICANN's transfer policy generally applies a 60-day lock on a domain after a change of registrant or a transfer between registrars. That is not an agency stalling you; it is policy. Plan your move with that window in mind rather than discovering it on the day.

The thing we would not buy

The offer to avoid is the all-in monthly website package on a proprietary platform — "a website, hosting, unlimited edits and support for ₹2,499 a month" — where the site is built on the provider's own builder rather than on software you could move. It looks like low risk because there is no large upfront bill. It is the opposite. Three years in you have paid more than a straightforward build would have cost, you have no exportable site, and if you leave you start from zero. Ask one question: if I cancel, can I take a working copy of this site to another host? On a proprietary builder the honest answer is no, and a vague answer means no.

The second thing we would not buy is a build where the agency insists on registering the domain in its own name "for technical reasons". There are no technical reasons. Managing a domain requires access, not ownership.

The third — and this one an agency could happily sell you — is a paid "website ownership audit" as a standalone service. You can do most of it yourself in an afternoon: run an RDAP lookup on your domain, log into your registrar and host, open Analytics and check whether you are listed under Account Access Management as an Administrator, and open your Google Business Profile to see whether you are Owner or Manager. If any of those fail, that is the conversation to have — but you found it for free.

If you have already signed and nobody mentioned any of this

Most existing sites in India were built without any of these clauses, and the relationship is usually perfectly fine. You are not accusing anyone of anything by tidying it up. A short, friendly email works: "We're putting our digital assets on record for the accounts. Could you confirm which registrar the domain sits with, and add [email] as an owner on the analytics and Business Profile?"

Do it while things are good. Requests made during a happy relationship get answered. Requests made during a breakup get ignored.

Order of priority if you can only fix a few things this month: domain first, then business email, then Google Business Profile, then hosting access, then analytics. That is roughly the order in which losing something hurts.

What to do next

Take twenty minutes. Open your registrar and confirm you can log in and see your domain, and check the expiry date while you are there. Open Google Analytics and confirm you are an Administrator on the account, not just a viewer on the property. Open your Google Business Profile and check whether it says Owner next to your name. Write down what you find, including the gaps.

If the exercise turns up something you cannot resolve — a domain in a former developer's name, a site you cannot back up, a Business Profile you cannot claim — that is a specific, fixable problem, and it is worth fixing before you commission anything new. We are happy to look at what you have and tell you where the gaps are; you can see how we approach building and rebuilding business websites, or get in touch with your findings. If the site itself is sound and only the access is tangled, that is often a support job rather than a rebuild.

Questions we get asked

How do I check who legally owns my domain name?

Use any public WHOIS or RDAP lookup tool and enter your domain. It will show the registrar and, unless privacy protection is switched on, the registrant name and contact email. If privacy is enabled, log into the registrar account itself — if you cannot log in, that is the answer you were looking for.

My developer has disappeared and holds my domain. What can I do?

Contact the registrar directly with proof that your business is the intended holder — invoices, payment records, correspondence, company registration. Registrars have dispute processes, and for .in domains there is a formal dispute resolution policy. It is slow and not guaranteed, which is exactly why registering in your own name from the start matters.

Should my agency host my website, or should I buy hosting myself?

Either is fine as long as the arrangement is written down. Agency-managed hosting is often better maintained than a cheap plan bought unsupervised. What you need is a clause saying you can obtain a full backup of files and database on request, and that the site can be moved elsewhere if the relationship ends.

Do I own the code if I paid for a custom website?

Not automatically. Under copyright law the person who wrote the code generally owns it unless the contract assigns it or grants you a licence. Ask for either copyright assignment on final payment or a perpetual, transferable licence to use and modify. Most developers agree readily when asked before the work starts.

Can I move my website away from a monthly website-builder package?

Usually not in any useful form. Proprietary builders typically let you export text and images but not a working site, so you are rebuilding from scratch elsewhere. Before signing any monthly package, ask in writing whether you can take a working copy to another host on cancellation.

If this is your problem

What we’d actually do about it.

All posts

Start here

Want us to look at yours?

Send the URL and what you think is wrong. We’ll tell you what we see, whether or not you hire us. Reply within 1 business day.

What do you need?

We reply within 1 business day. No newsletter, no sales sequence.