Who actually owns your website? Domain, code, hosting and accounts
Most business owners discover the answer to this question at the worst possible moment: when they want to change agency, or when the agency stops replying. The website is not one thing you own, it is four separate things, and it is entirely possible to have paid in full for all of them while controlling none.
The four separate things people call the website
The first is the domain name, which is the address people type. It is rented from a registrar, usually annually, and whoever is listed as the registrant controls it.
The second is the code and design: the theme, the templates, the custom functionality and the images. This is intellectual property and its ownership is decided by contract, not by who paid the invoice.
The third is the hosting: the server the files sit on and the account that pays for it. Losing access here means losing the ability to move, back up or fix anything.
The fourth is the surrounding accounts: Google Analytics, Search Console, Google Ads, Business Profile, the email service, the payment gateway. These hold your historical data and often more commercial value than the site itself.
You can own any combination of these four. The common and painful case is owning the code but not the domain, which means you have a website you cannot publish at your own address.
The domain is the one that matters most
If you own only one of the four, make it the domain. Everything else can be rebuilt in weeks. A domain held by someone else can take months of dispute, or a payment, or simply never come back.
The registrant, sometimes called the owner or the registrant contact, is the legal holder. The administrative and technical contacts are roles, not ownership, and being listed as admin contact does not give you control.
For .ee domains the Estonian Internet Foundation requires the registrant to be a real identified person or company, which is a genuine protection, but it also means a domain registered under the agency's company belongs to the agency.
Check yours today. For .ee domains use the registry's whois lookup, and for .com and similar use any public whois service. If privacy protection hides the details, log into the registrar account and look at the registrant field directly.
If the registrant is your agency, ask for a transfer in writing. It is a standard, routine process: they unlock the domain, give you an authorisation code, and you move it to a registrar account in your own name.
Do this while the relationship is good. A transfer request during a dispute is a very different conversation from one made as ordinary housekeeping.
Code, licences and what custom really means
In most European jurisdictions, copyright in commissioned work belongs by default to the creator, not to the client who paid for it, unless the contract says otherwise. Paying an invoice is not the same as acquiring the rights.
So the contract needs an explicit clause. Either the rights transfer to you on final payment, or you receive a broad perpetual licence to use, modify and move the work. Either is workable; silence is not.
Third party components are a separate layer. A premium theme, a paid plugin, a stock photo licence and a font licence each have their own terms, and some are tied to the buyer's account rather than to your site.
Ask specifically which licences are registered to you and which sit under the agency's account, because the second kind stop updating the moment you part ways, and unupdated plugins are the most common route into a hacked site.
For a truly custom build, ask where the source code lives. A repository you have access to is worth more than a zip file emailed at handover, because it carries the history and lets any future developer understand what was done.
Fonts deserve a specific mention because they are the most frequently mishandled item. A desktop font licence does not cover use on a website, and the invoice that eventually arrives goes to the site owner, not the designer.
Hosting, accounts and the data that is really yours
There are two common hosting arrangements. Either you have your own account with a provider and give the agency access, or the agency hosts you on its own infrastructure and bills you for it.
The second is not automatically bad, and for small sites it is often cheaper and better managed. It becomes a problem only when you cannot get a full export of files and database on request.
So make that the test question: can I receive a complete backup of the site, files and database, within a few working days if I ask? An agency that answers yes without hesitation is not holding you hostage, whatever the arrangement.
Analytics accounts follow the same logic. Google Analytics and Search Console properties should be created under your own Google account, with the agency added as a user, and never the other way round.
The reason is that data does not transfer. If a Google Ads account is closed, its conversion history and learning go with it, and a new account starts from zero at a higher cost per result.
The same applies to your Google Business Profile, which is frequently created by an agency and then effectively lost. Claim ownership of it yourself and add anyone else as a manager.
How to check what you own today
This takes about an hour and is worth doing even if you are happy with your current supplier.
- Run a whois lookup on your domain and confirm the registrant is your company or you personally.
- Log into the registrar account yourself. If you cannot, you do not control the domain regardless of what whois says.
- Confirm you have an administrator login to the hosting control panel, and download one full backup so you know it is possible.
- Open Google Analytics, Search Console, Ads and Business Profile and confirm your own account holds the owner or administrator role in each.
- Confirm you have an administrator account on the CMS itself, not an editor account.
- Collect the licence details for any paid theme, plugins and fonts, and check whose name they are registered in.
Anything that fails these checks is a request to make now, in writing and without drama, as part of normal record keeping.
What to put in the contract next time
Four short clauses prevent almost every version of this problem, and no reputable supplier objects to them.
State that the domain is registered in the client's name and that the client holds the registrar account.
State that on final payment all intellectual property in the delivered work transfers to the client, or that the client receives a perpetual, transferable licence to use and modify it.
State that the client is entitled to a full export of files and database on request, and set a reasonable deadline such as five working days.
State that all analytics, advertising and business accounts are created under the client's ownership with the supplier granted access.
Add one practical item that is not legal at all: a handover document listing every service, login location and renewal date. When someone new takes over your site in three years, that page saves days of work and is the single most useful thing an agency can leave behind.
FAQ
I paid for the website in full, so surely I own it?+
Paying settles the invoice, but in most European jurisdictions copyright in commissioned creative and software work stays with the creator unless the contract explicitly assigns it, so full payment and full ownership are genuinely two different things. In practice this rarely causes conflict while a relationship is working, and it matters intensely at the moment you want to move the site elsewhere or hire a different developer. The fix is not adversarial: ask for a short written confirmation that rights transferred on final payment, or a perpetual licence to use and modify the work, and most suppliers will provide it without hesitation.
My agency registered the domain in its own name. Is that a problem?+
It is worth correcting, because the registrant is the legal holder and everything else about your online presence depends on that address continuing to point where you want it to. The correction is routine rather than dramatic: the current holder unlocks the domain and issues an authorisation code, you open an account with a registrar in your own company name, and the transfer completes in a few days. Do it while relations are good, because the same request made during a disagreement turns an administrative task into a negotiation, and in the worst case leaves your email and website hostage to it.
Is it bad if the agency hosts my site on its own server?+
Not inherently, and for a small business it is often the cheaper and better maintained option, since a managed environment with someone watching updates beats a neglected account at a budget provider. The single condition that makes it safe is portability: you should be able to request and receive a complete export of files and database within a few working days, no questions asked. Ask that question directly before you sign, and take a full backup yourself once a year so you know from experience that the answer is real rather than theoretical.
