Who Actually Owns Your Website?
The phone call goes roughly like this. A company wants to move to a new agency, or just wants their site updated by someone else, and discovers that they cannot. The domain is registered to their old supplier. Or the site only runs on a platform they do not have an account for. Or nobody knows where the source code is.
This is more common than it should be, and it is almost always preventable with two emails at the start of a project. Here is what to check.
The five things
1. The domain name. This is the one that matters most, because everything else depends on it. Your domain should be registered with you as the registrant, using your email address, in an account you can log into. An agency managing the renewal for you is fine. An agency being the legal owner is not.
The failure mode is nasty: if the relationship ends badly, or the agency simply goes quiet, your email and your website both stop working and you have very little leverage. Recovering a domain you do not own is slow, sometimes expensive, and occasionally impossible.
2. The source code. Whatever the site is built from — templates, theme files, custom components, configuration — should be in a repository you have access to. Not a zip file someone promises to send if you ask.
If the site was built on a proprietary platform that only that agency can run, you do not have a website. You have a subscription, and the price of leaving is rebuilding from scratch.
3. The hosting and infrastructure accounts. The hosting account, the DNS, the SSL certificates, the CDN, the database. These should be in your company's name with billing to your company, even if the agency has access to manage them.
A reasonable arrangement is that you own the accounts and add the agency as a collaborator. That way, changing agency is a permissions change rather than a migration project.
4. The content. The text, photographs and video. If the agency wrote your copy or shot your photos, the contract should say the rights transfer to you on final payment. This is frequently left ambiguous, and copyright defaults are not always in your favour.
Stock images are a special case. Licences are usually issued to whoever bought them and are often non-transferable, so a site full of stock photos licensed to your ex-agency is a problem. Ask which images are licensed to you.
5. The data accounts. Analytics, Search Console, the ad accounts, the newsletter list. Years of historical data live in these, and they are worth more than most people realise. Own the account; grant access.
Why this happens
It is worth saying plainly that this is not usually malice. Most of the time an agency sets everything up under their own account because it is faster, they were going to manage it anyway, and nobody asked. Then five years pass and the arrangement is suddenly load-bearing.
There is a minority who do it deliberately, because a client who cannot leave does not leave. You can tell them apart with one question: "if we part ways, how do I take everything with me?" An honest agency answers in a sentence. Someone who benefits from the lock-in gets vague.
What it costs you when you get it wrong
Three concrete costs.
Leverage. If you cannot leave, you have no negotiating position on price or response time. That shapes every conversation you have for years.
Continuity risk. Agencies close, get acquired, or lose the one person who knew your setup. If your business depends on infrastructure held in someone else's name, that is a single point of failure with no plan behind it.
Rebuild cost. Moving off a proprietary platform is not a migration, it is a new project. Companies routinely pay for their website twice because of a decision nobody noticed making.
What to do if you are already in this position
Do not start with a confrontation. Start with an inventory.
- Check the domain. Look up your domain in a public WHOIS lookup and see whose name and email are on it. This takes thirty seconds and answers the most important question.
- List where things live. Which platform runs the site, who holds the hosting login, where the code is, who owns the analytics property.
- Ask, plainly and without drama. Most agencies will simply transfer things when asked. Something like: "we are tidying up our records, can you transfer the domain to our account and add us as owners on hosting and analytics." Ordinary housekeeping, and it usually just happens.
- If you meet resistance, that is important information. Get the request in writing, check your contract, and consider whether this is the right supplier regardless.
Put it in the contract next time
Four lines in a proposal prevent all of this:
- The domain is registered in the client's name, in an account the client controls.
- All source code is delivered to a repository owned by the client.
- Hosting and third-party accounts are in the client's name; the agency has delegated access.
- Copyright in commissioned content transfers to the client on final payment.
Any agency comfortable with those four lines is one you can work with. Any agency that argues about them has told you something useful before you have spent a euro.
The principle underneath
An agency should keep your business because the work is good, not because leaving is painful. If your supplier is confident in what they do, they have no reason to hold your domain.
The reverse is also true, and worth remembering: owning everything is not an argument for leaving. Most companies who sort this out stay exactly where they are. They just stay by choice, which is a much better basis for the relationship on both sides.
Keep reading
Need help with your project?
Get direct, personal advice on your project — response within 24 hours, in English, Dutch or Spanish