The question nobody asks until it hurts
Most business owners would say they own their website. They paid for it, it has their name on it, it is obviously theirs. Then the developer stops replying, or the agency closes, or a relationship sours, and it turns out the domain is registered to somebody else, the hosting is on somebody else's card, and nobody knows the admin password.
Ownership of a website is not one thing. It is three separate accounts, each with its own login, each of which can be in your name or somebody else's. Here is what they are, why each one matters, and how to check where you stand in about twenty minutes.
1. The domain
The domain is your address: yourbusiness.com. It is registered through a registrar, a company like Namecheap, GoDaddy, Cloudflare or 123 Reg, and it is the one thing you cannot rebuild if you lose it. Everything else on this list can be replaced. A lost domain means a new address, reprinted signage, dead links from every directory that lists you, and a competitor who may buy the old one.
Who should hold it: you. In an account with your own email address and your own card. Not the developer's account, not the agency's, not a "we manage it for you" arrangement.
How to check: run a WHOIS lookup on your domain. If privacy is on, the registrant will be hidden, so check whether you have a login to the registrar. Search your email for "domain renewal". If you find nothing, the domain is in someone else's account, and the first email you send tomorrow should politely ask for it to be transferred to yours.
What good looks like: you can log in to the registrar, you can see the expiry date, the payment card is yours, and auto-renew is on.
2. The hosting
Hosting is the computer your website's files and database live on. It is a separate account, usually at a different company from the domain, and usually billed monthly or yearly.
If the hosting lapses, the site goes offline. If the developer holds the hosting and disappears, your site is one declined card away from vanishing, and you have no way to log in, back it up, or move it.
Who should hold it: you, on your own card. A studio can still do the work inside it. Most hosts let you add a developer as a collaborator with their own login, which is the right arrangement: you own the house, they have a key.
How to check: look for a monthly or yearly charge on your statements that you do not recognise, and search your email for "hosting", "cPanel", or "server". If you are not paying for hosting, someone else is, and that someone controls your site.
What good looks like: you can log in, you can see the renewal date and the backups, and you could download a full backup of the site right now if you wanted to.
3. The logins
The admin login gets you into the site itself, to change a price or add a page. For a WordPress site it is usually at your address followed by /wp-admin. There are often more: the booking system, the email service that sends form submissions, the analytics account, the Google Business Profile.
Who should hold them: you, as the owner of each account, with the developer given their own separate login where they need one. Shared passwords are how access gets lost when people move on.
How to check: try to log in to each one. If the password reset email goes to an address you do not control, the account is not yours in any practical sense.
What good looks like: a simple list, kept somewhere safe, of every account the business depends on, the email it is registered to, and who else has access. One page. Update it when anything changes.
The lock-in patterns to recognise
Some arrangements are designed, deliberately or by laziness, to keep you dependent.
- "Hosting included." Convenient, and it means the site lives in the developer's account. Ask for it to be in yours, with them as a collaborator.
- "We registered the domain for you." Fine as a favour, if it is transferred to you afterwards. Not fine if it stays in their account.
- Handover fees. If leaving costs money beyond the final invoice, the price of leaving was hidden in the price of staying.
- No admin login "for security". Restricting what an untrained editor can break is reasonable. Refusing the owner any login is not.
- A care plan you cannot cancel without losing something. A plan is a service. Cancelling it should stop the service and nothing else.
None of these is proof of bad faith. All of them are worth a direct question.
What we do, and why
Every site we build has the domain, the hosting and every login in the client's name, with us added as a collaborator where we need access. It is stated on the pricing page because it is a selling point and because it should be: a studio that has built lock-in into its business model is telling you something about how it expects to keep clients.
At handover you get a recorded walkthrough and a one-page list of every account. If you leave, nothing needs handing over, because you already have it.
The twenty-minute check
- WHOIS your domain. Find the registrar login. Confirm the expiry and the card.
- Find the hosting charge on your statements. Find the login. Download a backup.
- Log in to the site admin. If you cannot, find out whose email the reset goes to.
- List every other account: booking, email, analytics, Google Business Profile.
- Write it all on one page and put it somewhere two people can find.
If any of those steps stalls, that is the one to fix this week, before the day you need it. If you would like someone to run the check and hand you the list, it is part of what a website diagnosis covers.