Who owns your website? A checklist for Philippine businesses. Dthree Insights cover
Business
6-minute read

By:

Hans Allí

Who Owns Your Website? A Checklist for Philippine Businesses

A few months ago a company came to us for a redesign. The old site was fine for its time, the team had a clear brief, and the budget was ready. Then we asked a routine question: who has the login to the domain? Nobody knew. The site had been built years earlier by a freelancer who had since moved abroad, and the domain was registered under a personal email. The company had paid for everything. It owned none of it, in the sense that mattered.

Nobody in that story did anything wrong. The freelancer set things up the fastest way, the company trusted them, and it worked until the day it did not. We see some version of this on most of the sites we inherit, so this guide is the checklist we walk clients through, written so you can run it yourself in an afternoon.

What owning a website actually means

A website is not one thing. It is a name, a place, and the site itself, held together by a handful of accounts. You own the website when your company, not a person and not a vendor, is the account holder on each of them. Access is a different thing from ownership: a vendor can and should have access to do their work, but the account should belong to you, so that access is something you grant and can withdraw.

The distinction sounds academic until a relationship ends, a staff member leaves, or a renewal email goes to an inbox nobody reads. Then it is the whole problem.

The seven things to check

1. The domain. This is the one that matters most, because everything else can be rebuilt and the name cannot. Every domain has a registrant on record, and the registrant is the owner in the eyes of the registry. Ask for the registrar login and look at the registrant contact. It should be your company, with a company email address, not a vendor and not a former employee. Note the renewal date while you are there. For a .ph domain, the registry is dotPH, and changing the registrant means a signed form and a government ID sent to their helpdesk, which is manageable but takes cooperation from whoever is currently on record. For .com and other generic domains, a change of registrant triggers a 60-day lock on moving the domain to another registrar, so plan any registrar move around it.

2. The DNS. The nameservers decide where your domain points, and they are sometimes managed somewhere other than the registrar, at Cloudflare or at the host. Know where. If your email runs on Google Workspace or Microsoft 365, the records that make it work live here too, which is why a DNS mistake can take down your mail along with your site.

3. The hosting account. The server or platform account where the site files live. It should be in the company's name, billed to a company card, with a company email on the account. If a vendor hosts your site inside their own account, that is not automatically bad, but you should know it, have it written into your agreement, and have a plan for what happens if you part ways.

4. The site platform. On WordPress, this is an administrator account that belongs to your company, not only the vendor's. On Webflow, the site should sit in a workspace your company owns; agencies can transfer a site, plan and custom domain included, to a client workspace, and can then be added back as a guest to keep working on it. That is how we set up Webflow builds, and it is the arrangement to ask for.

5. Analytics and Search Console. Google Analytics and Search Console hold your traffic history and your standing with Google. In Search Console specifically, there are verified owners and delegated owners, and a delegated owner loses access if the verified owner who added them is removed. Your company should hold a verified owner seat of its own.

6. Business email. If your email domain is the same as your website domain, which it usually is, then the domain checklist above protects your email too. Separately, the Google Workspace or Microsoft 365 tenant should have a super admin that is a company role, not a departed employee's personal account.

7. Google Business Profile and social pages. Your Google Business Profile has exactly one primary owner, and if an agency claimed it for you, they may still be that owner. Transferring it is a few clicks, followed by a seven-day wait before the new owner has full control. On Meta, the same principle applies: your business portfolio should own the Page, pixel, and ad account, and agencies should have partner access, which you can revoke in one place. We set our own social media clients up this way for the same reason.

How companies end up here

The pattern is almost never bad faith. A vendor registers the domain because the client does not have a credit card ready and launch is Friday. A marketing manager creates the Google Business Profile with a personal Gmail because that was the only account open at the time. The IT person who set up the hosting leaves, and the password goes with them. Each step made sense that day.

The Philippine wrinkle is that many small vendors are one-person operations, and a person can move abroad, change careers, or simply stop answering messages. That is not a criticism of freelancers: several of the best builders we know work alone. It is a reason to make sure the accounts do not depend on any one person, including us.

How to ask your vendor

This conversation does not need to be awkward. Most vendors will help readily, and the ones who do not are telling you something. A short message covers it:

We are doing an audit of our digital accounts. Could you confirm where our domain is registered and who the registrant is, and help us move the domain, hosting, and site admin accounts under a company email? You would keep full access to do your work. Happy to cover any time this takes.

The tone matters. You are not accusing anyone; you are tidying up. Offer to pay for the hours, because moving accounts is real work, and set a date to review it together.

What a good handover looks like: the domain registrant is your company, you hold the registrar and hosting logins in a company password manager, the site platform has a company-owned administrator or workspace, and your vendor works through access you granted. Renewal dates for the domain and certificate are in a calendar that more than one person can see.

Where we stand on this

We build the site, and you own it. On every project, the domain and platform accounts are created under the client's name or moved there before launch, and we work from access the client can revoke. Where we host a site on a client's behalf, that arrangement is written into the agreement with a clear handover path, so it never becomes a reason to stay. It occasionally costs us a little convenience. It means that when a client leaves, which happens, they leave with everything, and when they stay, they stay because they want to.

If you have just run this checklist and found gaps, that is normal, and most of them take a few emails to close. If the gaps involve a vendor who has gone quiet, or a domain in someone else's name, talk to us. Recovering access is something we have done many times, and it is easier before a renewal lapses than after. For what it costs to keep a site properly maintained once the accounts are yours, our guide to website maintenance costs covers the full picture, and if you are starting a new project and want to see how the accounts get set up from day one, here is what happens after you reach out.

Three men standing indoors, smiling, with one wearing a white zip-up shirt, another in a black button-up shirt and glasses, and the third in a blue checkered shirt with arms crossed.

Co-founders Imat Marasigan, Hans Allí, and Mon Baldonado

Smiling young man looking at his smartphone while sitting at a table with a silver Apple laptop.
Start a project
Scroll to top