You should own your website, but "should" and "do" are often different answers. A website isn't one thing. It's at least eight: the domain, the hosting account, the code and design, the theme and plugin licenses, the content, the analytics and ad accounts, the Google Business Profile, and email. Each has its own owner, set by whose name is on the account and what your contract says.
So does your web designer own your website? If they registered the domain in their own account, host the site on their server, and your contract says nothing about copyright, then in practice they control most of it, even if you paid for every hour. The good news is that each piece takes about five minutes to check, and most can be fixed with a polite written request.
This is general information, not legal advice. For contract terms or a dispute, talk to a lawyer licensed in your state.
- The domain matters most. The registrant should be your business, in a registrar account you log in to, on auto-renew.
- Under US law, custom code and design from an independent contractor usually belong to the contractor unless there's a signed written agreement saying otherwise.
- Premium themes, plugins, fonts and stock photos are licensed, not owned. Find out whose account holds each license.
- Analytics, ad accounts and your Google Business Profile should be owned by a login your business controls, with agencies added as users or partners.
- Email depends on your domain's DNS. Whoever controls the domain can redirect your email.
Who owns each part of your website
| Piece | Who often ends up with it | Who should own it |
|---|---|---|
| Domain name | Whoever registered it, often the designer | Your business, as registrant and account holder |
| Hosting account | The agency, bundled into a monthly fee | Your business, with the developer as a user |
| Custom code and design | The creator, unless a signed contract says otherwise | You, by written assignment, or a clear license |
| Themes, plugins, fonts, stock photos | Licensed to whoever bought them | Licensed to you, or a documented handover |
| Text, photos, logo | Mixed: yours, the designer's, or stock | You, with original files on hand |
| Analytics, Search Console, ad accounts | Whoever created them | Your business login, agency as user or partner |
| Google Business Profile | Whoever verified it first | You, as primary owner |
| Your email provider, routed by the domain's DNS | Your business, as the admin |
The domain: registrant vs account holder
Two different things decide who controls a domain:
- The registrant is the legal holder named in the registration record.
- The account holder is whoever logs in to the registrar where the domain is managed.
They're often different people. A designer registers the domain "to keep things simple," and the registrant is your business, but the account is theirs. Or the reverse: it's in your account, but the registrant contact is the designer's email. You want both to be your business.
How to check in five minutes
- Look up your domain at ICANN Lookup, which uses RDAP, the system that replaced WHOIS for generic domains like .com. Note the registrar, the expiry date and the nameservers.
- The registrant's name is usually hidden for privacy, so log in to the registrar it names. If you can't, because you've never had an account there, that's your answer: someone else holds it.
- Inside the account, open the domain's contact details and confirm the registrant is your business, with an email address you control. Turn on auto-renew with a card that won't expire.
Don't be thrown if the registrar is a company you've never heard of. Domains bought through a website builder often list a wholesale registrar you don't recognize as the registrar of record. You manage the domain inside the builder, and that's fine as long as the builder account is yours.
If the domain is in someone else's account, ask them to move it into yours. Most registrars support an account-to-account move without changing registrar, and it's quicker than a full transfer. Our website takeover checklist covers transfer codes and ICANN's 60-day locks.
Watch out: The domain also routes your email. Whoever controls its DNS can point your mail somewhere else, or break it by accident. That's why the domain comes first on this list.
Hosting: who holds the account
Hosting is where the site's files run. The question isn't who pays the bill, it's whose account the site lives in.
- Your own hosting account (for example WP Engine, Netlify or a builder plan in your name), with the developer invited as a user: you can change developers by changing users.
- The agency's server or account: your site is one of their customers' sites. You'll depend on them to export it if you leave.
- Website builders: the site can't leave the platform as-is, but it can usually change accounts. Wix, for example, lets you transfer a premium site to another Wix account.
Five-minute check: try logging in to the host yourself. If you don't know which host it is, the IP address from nslookup yourdomain.com 8.8.8.8 and the page source usually tell you.
The code and design: who owns the copyright
This is where "I paid for it, so I own it" goes wrong. Under US copyright law, the person who creates a work generally owns it. The exception is a "work made for hire," which the US Copyright Office's Circular 30 describes in two situations:
- Work created by an employee as part of their regular duties. The employer owns it.
- Work specially commissioned from someone else, but only if it falls into one of nine specific categories (such as a contribution to a collective work or a compilation) and both parties sign a written agreement saying it's a work made for hire.
A website from an independent designer doesn't fit neatly into those nine categories. So a contract that only says "work for hire" may not be enough on its own. That's why careful contracts also include a written assignment of copyright. Under 17 U.S.C. § 204, a transfer of copyright ownership must be in writing and signed by the owner.
With neither in place, the designer usually still owns the copyright in their custom code and design, and you have a license to use it. The scope of that license may be unclear, which is exactly when disputes start.
Two reasonable exceptions to expect in any contract: developers keep the general tools and code they reuse across clients (and license them to you), and they may ask to show your site in their portfolio.
Not legal advice: copyright and contract rules vary with the facts and the state. If ownership of your site is in dispute, or you're signing a large contract, have a lawyer review it.
Themes, plugins, fonts and stock photos are licensed, not owned
Most sites are built partly from things nobody on the project created.
- WordPress itself is licensed under the GPL, and WordPress's position is that themes and plugins inherit it. What you pay for with a premium theme or plugin is usually the license key, which brings updates and support. If that key sits in your developer's account and they stop renewing it, your site stops getting updates, which becomes a security problem.
- Web fonts from a subscription service are tied to the account that set them up.
- Stock photos are licensed to whoever bought them, under that license's terms.
- Builder templates are used under the platform's terms.
Five-minute check: in WordPress, open the Plugins page and note every premium plugin and the theme. Ask your developer for a list of each license, whose account holds it, and when it renews. For photos, ask for the license record or the original file source for each image.
Your content: text, photos and customer data
Text you wrote and photos you or your staff took are generally yours. Copy the designer wrote and photos they took fall under the copyright rules above, so cover them in the contract. Either way, keep the original files yourself, not just the versions on the site.
Don't forget the data the site collects. Contact and booking forms store submissions in the site's database or send them to an inbox. That's your customer list. In work we did for Elume Medspa, the site's booking request form held 1,897 entries from 1,331 people going back to 2018.
Analytics, Search Console and ad accounts
These accounts hold years of history you can't recreate: traffic data, conversion tracking, ad performance and billing. They should be created under a login your business controls, with agencies added as users.
- Google Analytics: Admin, then Account access management. You want Administrator.
- Search Console: Settings, then Users and permissions. You want Owner.
- Google Ads: Admin, then Access and security. You want Admin, and the payment profile should be your business.
- Meta: in Business settings, check which business portfolio owns the ad account and Page. Meta doesn't move ad accounts between portfolios, so an ad account created in an agency's portfolio stays there.
From our work: In work we did for Elume Medspa, we found four Meta ad accounts spread across two Business Managers, with a legacy video ad still running. On the Google side, the Shopify store was still linked to a paused 2022 Google Ads account that had failed advertiser verification, while the live account was a different one. Accounts pile up when different people set things up over the years. Untangling them started with one question for each account: whose is it?
Google Business Profile
Your Business Profile drives your map listing, reviews and calls, and it isn't part of your website at all. It has one primary owner, plus other owners and managers. Managers can edit almost everything but can't add or remove people. Per Google's help page, a new owner has to wait 7 days before they can transfer primary ownership or remove other owners.
Five-minute check: open your profile's settings, then People and access. Your business login should say Primary owner. Your agency should be a manager.
Your mailboxes live at Google Workspace, Microsoft 365 or another provider. You should hold the admin login there, not the developer. But email also depends on the domain: the MX records in your DNS decide where mail is delivered, and the SPF, DKIM and DMARC records decide whether your outgoing mail is trusted. Whoever controls the domain controls those records.
Five-minute check: log in to your email admin console and confirm you're a super admin. Then check that the domain itself passes the test in the domain section above.
What to put in your website contract
- Domain: registered to your business, in your account, with the developer given delegated access if needed.
- Hosting: in your account, or a written commitment to export the full site (files and database) within a set number of days if you leave.
- Copyright: a signed assignment to you of the custom design, code and copy on final payment, plus a license for any reusable tools the developer keeps.
- Third-party licenses: a list of every premium theme, plugin, font and stock image, whose account holds it, and how it transfers.
- Accounts: analytics, Search Console, ad accounts and Business Profile created under your business login.
- Credentials: you hold your own admin login to everything, from day one.
- Exit: what the developer hands over if either side ends the agreement, in what format, by when, and at what cost.
Our rule: you own everything
When we build or take over a site, the domain stays in your account, in your name. We never move it into ours. We work through access you grant and can revoke. At GoDaddy, for example, Delegate Access lets us work on your products without seeing your payment methods or password. The site, its files, your photos and your content belong to you. Booking, email, Business Profile and ad accounts stay in your name. If you ever want to leave, we hand over every file and login and help you move, at no charge.
Not sure where your site stands? We'll check it as part of a free audit. Or see our website design service for how we build sites you own outright.
Frequently asked questions
Can my web designer keep my domain if I stop paying them?
If the domain is registered to your business, the registrar must give you the transfer code on request, and the designer can't keep it. If it's registered to the designer or sits in their account, you'll need their cooperation, which is why the registrant name and account should be yours from the start.
Do I own my website if it's built on Wix or Squarespace?
You own your content and your domain if it's in your name, but the site itself runs on the platform under its terms and can't be moved to another host as-is. Make sure the site lives in an account you own, with the designer added as a contributor.
What happens to my website if my web designer goes out of business?
If the domain, hosting and site are in your accounts, very little: you hire someone else and give them access. If they're in the designer's accounts, renewals can lapse and the site can go offline, so move them into your name while the designer is still reachable.
Who owns the photos on my website?
Photos you or your staff took are generally yours. Photos your designer took, or stock photos they licensed, depend on your contract and the license terms. Ask for the original files and the license records for every image.