If You Can’t Leave Cleanly, You Don’t Own the Site
If domain, hosting, code, CMS, DNS, and analytics aren’t in your accounts, you don’t own the site — you only rent access until your designer disappears.
William Spurlock Founder — Spurlock Studios Updated 20 MIN
If you want to leave your web designer and cannot take the site with you in a weekend, you do not own it — no matter what the sales call promised. “You always own everything” is a common AI answer and a frequent agency half-truth. Ownership is not a vibe. It is domain registrant, hosting billing, code or project access, CMS seats, DNS, and analytics properties sitting in your accounts. This is operational handoff, not legal advice; a contract clause without logins is still a paper win. This spoke sits under Websites That Feel Like Films.
The short answer
- Ownership is a checklist of accounts and artifacts, not a sentence in a deck.
- Domain and hosting should be registered and billed to the client from day one.
- Handoff means credentials plus completed transfers, not a ZIP emailed “if you ask.”
- If the designer disappears, the failure points are registrar, host card, and admin seats.
- Write the exit into the agreement before build starts — recovery after a ghosting is always more expensive.
What does leaving your designer actually mean?
Leaving is not one event. It is several doors, and any one of them can keep the rest of the house.
| Door | What you need | What “stuck” looks like |
|---|---|---|
| Domain | Registrar login; you are the registrant | Domain renews on their email; transfer locked |
| DNS | Access to the DNS host (often registrar or Cloudflare) | Site points nowhere when they cancel |
| Hosting | Billing plus project transfer (Netlify, Vercel, Webflow hosting) | Site dies when their card fails |
| Code / project | Repo invite or platform transfer | No rebuild path without starting over |
| CMS | Editor/Admin seats you control | Cannot publish without them |
| Email / forms | Form endpoint plus inbox ownership | Leads go to a vanished inbox |
| Analytics | GA4 property in your Google account | History trapped in their login |
| Search Console | Property verified to your account | You cannot prove the site to Google |
If any row fails, your “owned website” is a dependency on a person. Pretty pages do not change that.
Who should own the domain from day one?
You. Always. From the first invoice if you can swing it.
ICANN’s transfer policy exists so the Registered Name Holder can move a gTLD between registrars when the gaining registrar’s process meets the minimums — not so a contractor can hold the name hostage. Read the policy at ICANN’s Transfer Policy. The holder-facing version is Inter-Registrar Transfer Information: you generally cannot transfer within the first 60 days after initial registration, or the first 60 days after a prior transfer. Cloudflare’s registrar FAQ repeats the same 60-day lock after registration, registrar change, or WHOIS contact change (Cloudflare Registrar FAQ).
That lock is why “we’ll transfer it later” is a trap. Later often lands inside a lock window, a redemption period, or a vanished inbox.
Best pattern:
- You create (or already have) a registrar account — Cloudflare Registrar, Namecheap, Route 53, or whoever you already pay.
- You are the registrant of record. The studio is a technical contact, not the name on the registration.
- Renewal notices go to a company inbox you control, not a freelancer’s Gmail.
- If the name already lives under them, start the transfer now, not at launch week, so the 60-day clock is not a surprise.
| Asset | Preferred owner | Studio role |
|---|---|---|
| Domain | Client registrant | Advisor / technical contact |
| DNS | Client (or client’s Cloudflare) | Temporary admin during launch |
| Hosting | Client org / team | Collaborator |
| Design files | Client receives exports | Shared source, not a hostage |
| Production secrets | Client password manager | Documented, not tribal |
If a studio insists the domain “has to” live under them for “convenience,” treat that as a risk flag equal to a vague quote. Convenience for them is lock-in for you.
Cloudflare Registrar can move a registration between Cloudflare accounts when both sides confirm, but settings in the source account do not come along, and the name is transfer-locked for 30 days after the move (inter-account transfer). Plan that move while people still answer email.
Who should own hosting, billing, and the deploy account?
Your org. Their card is a time bomb.
Every modern host treats the team or workspace as the owner, not the person who designed the homepage.
- Netlify. Each site belongs to a team. A Team Owner can transfer a project to another team where they are also an Owner or Developer, unless the team has blocked outbound transfers (transfer a project, team-owned sites). Transfers between teams with no shared members go through support. Enterprise teams often start with transfers blocked.
- Vercel. You must be an owner of the source team and a member of the target team. Settings → General → Transfer Project. Deployments, env vars, and domains move; the docs call the cutover zero-downtime (transferring projects).
- Webflow hosting. The Workspace that holds the site owns the site. Billing access is not ownership. Webflow says so in plain language (site ownership).
| Host | Transfer mechanic | What you must hold after |
|---|---|---|
| Netlify | Transfer project into your team | Owner on the team; your card; env vars documented |
| Vercel | Transfer project into your team | Owner/member on the target; payment method on the team |
| Webflow | Site transfer into your Workspace | You accept the transfer; you pay the Site plan |
| Framer | File → Transfer Project | You accept; you pick and pay the Site plan |
Preferred setup from kickoff:
- You create the host team / Workspace (or accept a transfer into it).
- Studio is invited as collaborator or guest with enough access to ship.
- Billing stays on your card so renewals do not depend on a contractor’s personal Amex.
- Deploy keys, Git integrations, and env vars are not tied to one person’s laptop.
A site that dies when their card fails was never yours in practice.
What files and logins must you receive at handoff?
Minimum clean exit package. Check these while they still pick up the phone.
- Domain registrar login, or proof you are registrant plus the transfer-auth / TAC process
- DNS access and a written record of critical records (A/AAAA/CNAME/MX/TXT)
- Hosting project ownership transfer completed, not promised
- Repository access (GitHub/GitLab) or platform project transfer (Webflow, Framer)
- CMS admin seat for at least one client owner
- Form destinations documented (Netlify Forms, Formspree, inbox, CRM)
- SSL / custom domain status confirmed on the new owner
- Google Analytics (or equivalent) property under a company Google account
- Google Search Console property verified under that same company account
- Font licenses and stock licenses that allow your use
- Content export (CMS CSV/JSON, or documented collections)
- Staging URL retired or redirected; production is the source of truth
- Password-manager share revoked for people who should not keep access
Pair this with a CMS people will actually use — see CMS Choices Clients Will Actually Use — because ownership without an edit path is still a trap.
Proof beats a folder of screenshots:
- You can log in without the designer on a call
- You can invite a second studio as a test
- You can deploy or publish a trivial change
- You can see GA4 realtime and Search Console coverage
If you cannot check those four, you are not done launching. You are renting.
Is code ownership the same as a login?
No. Ask which commercial model you are buying, then ask who can log in tomorrow. This is not legal advice. U.S. copyright defaults are narrower than most decks imply. The Copyright Office’s Circular 30, Works Made for Hire is the official overview: “work made for hire” is a statutory category, not a slogan you paste into a proposal. Independent-contractor sites often need an assignment or a clear license plus access. Have counsel read the clause for your jurisdiction.
| Model | What you get | Risk if someone vanishes |
|---|---|---|
| Assignment / work-for-hire (when it actually applies) | You own the custom code on paper | Still useless without the repo |
| License to use | Studio keeps IP; you may run the site | Renegotiate if you fork or resell |
| Platform project transfer | You own the Webflow/Framer project per platform rules | Export limits vary by tool |
| Template + customization | You own content; theme license may restrict | Read the theme license before launch |
“Who owns the code?” is incomplete without “who can log in tomorrow.” A license without access is a paper win.
On GitHub, access control is the practical law. Transferring a repository requires admin on the source and permission to create repos in the destination (transferring a repository). Transferring an organization means adding a new owner, updating billing, then removing yourself — and removing yourself does not update the card on file (transferring organization ownership). GitHub’s own continuity note: if an org has one owner, the work can become inaccessible if that person is unreachable; they recommend at least two owners (maintaining ownership continuity).
A repo on a freelancer’s personal account with you as a collaborator is not a company asset. A company org with two owners and the studio as an outside collaborator is.
Do you need Git access, or is a platform transfer enough?
If the site is code-based: yes, or an equivalent. You do not need to write TypeScript. You need a repo or organization membership so a future studio can take over without archaeology.
If the site is Webflow or Framer: Git may not apply. You need project ownership transfer and a clear statement of export limits.
Decision list:
| Situation | What “enough” looks like | What is not enough |
|---|---|---|
| Custom / Astro / Next on Netlify or Vercel | Your GitHub org owns the repo; host team is yours | A ZIP of dist/ and a smile |
| Webflow | Site lives in your Workspace after transfer | Editor seat on their Workspace |
| Framer | You accepted Project Transfer; you pay the Site plan | “We’ll stay on as owner for convenience” |
| Hybrid (code + CMS) | Repo and CMS owner seat | One of the two |
Ask, in writing:
- Can the project transfer to my account at launch?
- What exports exist if I leave the platform later?
- Who holds the Workspace or org seat that bills?
- Can I add another developer without you?
Git access is a means. A controllable source of truth is the end.
How do Webflow and Framer handoffs actually work?
Platforms have transfer buttons. They also have hard stops when the owner is gone.
Webflow. Freelancer and Agency Workspaces can transfer a site — paid Site plan, custom domain, unused plan time — into a client Workspace. The recipient must already have an account and must accept the request. After accept, the site leaves the studio Workspace. If you still need them, you add them back as a guest (transfer a site or plan). Transfers involving Enterprise, or out of Core/Growth, may require a downgrade to Starter first, which can take a published site down. Plan that.
Webflow’s ownership article is the one founders skip: if the site sits in a freelancer’s Workspace and they become unreachable, Webflow cannot transfer that account or export the site to you. They may let you update billing to keep it online. If billing dies, the site goes away (site ownership). An Editor seat on their Workspace is not an exit.
Framer. Project owner or workspace admin opens File → Transfer Project, enters your email, and chooses whether to remain an editor. You accept from the email. The site stays live; connected domains stay. The old Site plan is canceled and unused time is credited to the original owner; you pick and pay the plan going forward (transfer your site).
| Check | Webflow | Framer |
|---|---|---|
| Who can start the transfer? | Workspace owner / allowed Agency-Freelancer flow | Project owner or workspace admin |
| Do you have to accept? | Yes | Yes |
| Does the site stay up? | Yes on the supported Agency→client path | Yes |
| Who pays after? | Your Workspace / Site plan | You, after their plan cancels |
| If they vanish first? | Support may not move the project | You are stuck without an owner |
Transfer on launch day. “We’ll do it when you want to leave” is how sites become unrecoverable.
Who owns DNS, and why is it a separate door?
Registrar ownership and DNS hosting are not the same login. Plenty of brands own the name at one registrar and point nameservers at Cloudflare, the host, or a leftover agency zone.
If they control DNS, they can:
- Point the apex at a parked page
- Break email by editing MX
- Remove the Search Console TXT and make you fail verification
- Hold the zone hostage while the domain itself “belongs” to you on paper
Record the zone before anyone has a bad week.
| Record | Typical job | If you lose it |
|---|---|---|
| A / AAAA / CNAME | Site hostname | Site 404s or hits the wrong host |
| MX | Inbox | Email dies with the site |
| TXT (SPF/DKIM/DMARC) | Mail auth | Outbound mail starts failing |
TXT (google-site-verification=…) | Search Console / Workspace | You cannot prove the domain to Google |
| CAA | Which CAs may issue certs | SSL issuance surprises |
Checklist for the DNS door:
- You can log into the DNS host without them
- Nameservers are documented
- A/AAAA/CNAME/MX/TXT are exported (screenshot plus a zone file if the host offers one)
- DNSSEC state is known (Cloudflare inter-account moves require DNSSEC off first)
- The person who can edit records is on payroll, not a contractor’s personal login
Netlify-registered names have their own transfer path, and Netlify will not accept inbound registrar transfers from other registrars — you delegate DNS instead (transfer a domain). Know which product you bought: registration, DNS, or hosting. They are three invoices that people collapse into “the website.”
Who should own Google Analytics and Search Console?
Measurement ownership is website ownership’s quiet twin. A redesign argument without history is just vibes.
GA4. Add users at account or property level. You need the Administrator role to assign roles (add, edit, and delete users; access and roles). Administrator can add and delete users and grant full permissions, including to themselves. Editor can change property settings and cannot manage users. The client company should hold Administrator on a Google account or Google Workspace it controls. The studio gets Editor (or Administrator temporarily) — not the other way around forever.
Search Console. A Domain property covers http/https and subdomains and requires a DNS record, usually TXT (verify site ownership). That is why DNS access is not optional. URL-prefix verification (HTML file, meta tag) is weaker: it can vanish in a redesign, and it does not cover the whole domain.
Minimum:
- Company Google account (or Workspace) owns the GA4 property.
- Studio is added as Editor or temporary Administrator — not the sole admin.
- Search Console Domain property is verified with a DNS TXT you control.
- Property IDs live in the handoff packet.
If ads or pixels exist, list them. Orphan pixels in a departed freelancer’s Meta Business Manager are a classic “why did leads die” story that has nothing to do with design.
- You can open GA4 without their Google login
- You can add a new user yourself
- Search Console shows the Domain property as verified
- The verification TXT is in your DNS
- Ad accounts / pixels are listed with who owns the Business Manager
What breaks if the designer disappears?
Real failure modes, not horror fiction. I have shipped hundreds of production sites. The dirty exits rhyme.
Hosting on their credit card
Card expires, a dispute fires, or they cancel. The site goes offline. DNS may still point at a dead host. Support talks to the account owner — not you.
Domain on their account
Renewal notices go to them. They ignore or leave the industry. The name enters redemption. You discover it when email and website die the same week. Then you meet the 60-day transfer lock and a registrar dispute queue.
Sole Admin on the CMS or Workspace
Nobody left can invite a new designer. On Webflow, unreachable Workspace ownership is a documented dead end. You negotiate with a stranger or rebuild from screenshots.
Repo private to their personal GitHub
Even if you “paid for the code,” access control says otherwise until a lawyer gets involved. One-owner orgs fail the same way. Prevention beats recovery.
Analytics and ads in their Google account
You lose historical baselines. The next studio starts blind. You cannot prove the redesign “killed conversions” because you never owned the measurement.
| Failure | Immediate symptom | Recovery path |
|---|---|---|
| Hosting card | 404 / suspended project | New host + redeploy if you have code |
| Domain hostage | Transfer denied / email gone | Registrar dispute; sometimes months |
| CMS / Workspace sole admin | Cannot publish or transfer | Platform support with proof of business; no guarantee |
| No repo | Cannot change production | Rebuild; screenshots as design reference |
| Forms to their inbox | “No leads” | DNS/email forensics; lost lead history |
| GA4 / ads in their login | No history, pixels dark | Recreate properties; baselines start at zero |
Bravery is not a restore strategy. Account ownership is.
How do you write the exit into the agreement before build starts?
Paste a clause shape like this and have a lawyer customize it for your jurisdiction. I am not your attorney. This is an operations checklist dressed as contract language, not a form you should sign blindly.
- Client shall be registrant of the domain and payer of hosting from project start (or transfer within X days of kickoff).
- Upon final payment / launch, studio shall transfer project ownership, repository access, and admin seats within Y business days.
- Studio may retain read-only or collaborator access only with client written approval.
- Deliverables include the handoff checklist items listed in Exhibit A.
- Failure to transfer accounts is a material breach, not a “support ticket.”
Also specify what happens mid-project if the relationship ends: who owns WIP files, what is payable, and whether domain/hosting already in the client’s name stay there (they should).
| Clause to demand | Why it exists |
|---|---|
| Client is registrant from kickoff | Avoids the 60-day lock at the worst moment |
| Named transfer deadline after launch | “We’ll send it later” is not a date |
| Exhibit A = the login checklist | Scope arguments die when the list is attached |
| Mid-project kill fee + WIP ownership | Ghosting mid-build is common enough to price |
| Studio access after launch is revocable | You can fire them without losing the keys |
Vague answers in the sales call are answers. Get the names of the accounts in writing before anyone opens Figma.
How do you recover if you are already stuck?
Order of operations when someone vanishes. Still not legal advice — registrar and platform support will ask for business docs, and outcomes vary.
- Find the registrar. Use ICANN Lookup (RDAP, the successor to port-43 WHOIS). Note registrar, status flags (
clientTransferProhibited,redemptionPeriod), and the registrant email if it is visible. - Find the host. DNS targets reveal Netlify, Vercel, Webflow, Squarespace, and friends.
dig/ a DNS lookup on the apex andwwwis enough to start. - Contact platform support with invoices, domain proof, and the ID / business docs they require. Webflow’s own article says there is no guarantee they can move a Workspace you cannot prove.
- Preserve content — archive.org, screenshots, CMS exports if any login remains.
- Stand up a temporary page on a host you control while ownership fights proceed.
- Do not pay ransom casually — document everything. Sometimes a small transfer fee is pragmatic. Sometimes it is a pattern.
| You still have | Do this first | You probably cannot |
|---|---|---|
| Domain + DNS | Point at a new host; republish | Recover their CMS without a seat |
| Repo only | New host team; new domain later | Keep the old URL if the name is hostage |
| Live site, no accounts | Archive + screenshot everything today | Assume support will “just transfer it” |
| Billing access only | Keep the card alive while you negotiate | Treat billing as ownership |
Prevention is cheaper. If you are hiring now, day-one ownership is part of why custom work costs real money — and part of why the film-grade bar in Websites That Feel Like Films includes an exit, not just a hero.
What does a clean exit look like on paper?
Use this at kickoff and at launch. Print it. The launch packet belongs next to Launch Checklists for Brand Sites.
Accounts
- Domain registrant = client
- DNS login = client
- Hosting / Webflow / Framer workspace = client
- Git org membership or project transfer done
- CMS owner seat = a client staff member
- Password manager vault shared appropriately
- Two owners on the GitHub org (not one freelancer)
Proof
- You can log in without the designer on a call
- You can invite a second studio as a test
- You can deploy or publish a trivial change
- You can see GA4 realtime and Search Console coverage
- You can add a GA4 user without them
Paper
- License / IP terms match what you paid for (counsel, not a tweet)
- Font and image licenses transferred or listed
- Form and CRM destinations documented
- Env vars and deploy keys rotated off personal accounts
- Studio leftover access is read-only or gone
If you cannot check these boxes, you are not done launching.
What should a studio offer by default?
If a studio’s default is client-owned accounts, collaborator access, and a written handoff, they are selling a transferable asset. If their default is “we handle everything on our accounts,” they are selling a service dependency. Both can ship pretty pages. Only one survives a breakup.
Spurlock Studios’ bar for brand work is the film-grade craft in Websites That Feel Like Films and an exit you can execute without a forensic specialist. Craft without ownership is a beautiful leash. The websites lane is built that way on purpose — start at /websites if you want the build and the keys.
Clean. Client owns brand.com at their registrar. Netlify team is theirs; we are a collaborator. Webflow or Framer project transferred at launch. GA4 and Search Console under client Workspace. A manager publishes a tour date the next week without pinging anyone. Exit later is inviting a new collaborator and removing the old one.
Dirty. Freelancer registered the domain under a personal Gmail, hosted on their Vercel Hobby plan, and was sole Webflow admin. They stop answering. Card declines. Site dies on a Friday before a release. Content exists as a memory and a few Instagram screenshots. Rebuild starts from zero while the domain recovery ticket ages.
Same “we built you a website.” Opposite ownership outcomes.
What questions should you ask on the sales call?
Steal these. Write the answers into the statement of work.
- Whose name is on the domain registrant record at launch?
- Whose card pays hosting in month two?
- Will I be Workspace/org owner, or only an editor?
- What exact artifacts do I receive on handoff day?
- How do I add another developer without you?
- What happens to the site if we stop working together next quarter?
- Will GA4 and Search Console live under our Google account?
- If you become unreachable, which platform support path exists — and what does that vendor say they will not do?
Vague answers are answers. “We’ll take care of it” is how you rent a site that looks owned.
FAQ
Who owns the code after launch?
Only what the agreement says — plus what you can actually access. Prefer assignment or a clear license and a repo or project transfer into your account. Paper ownership without a login is incomplete. This is not legal advice; have counsel read the IP clause for your jurisdiction.
Can an agency keep my domain?
They can if they are the registrant. Do not allow that pattern. Be the registrant from day one, or start the transfer immediately after purchase with an auth code you control, and remember ICANN’s 60-day lock after registration or a prior transfer.
What if hosting is on their credit card?
Move billing and project ownership before launch week ends. Netlify, Vercel, Webflow, and Framer all have transfer flows — they require you to accept into a team or Workspace you own. A site that dies when their card fails was never yours in practice.
Do I need Git access?
For code sites, yes — or org membership that lets a future team take over. For Webflow or Framer, you need project ownership transfer and clarity on exports instead. A ZIP of the live files is a souvenir, not a source of truth.
What about Google Analytics and Search Console?
Both should live under a Google account your company controls, with the studio as an optional collaborator. Otherwise your history and verification leave with them. Use a Search Console Domain property verified by DNS TXT you control.
What is a clean exit checklist?
Domain, DNS, hosting, code or project, CMS seats, forms, fonts and licenses, GA4, Search Console, and proof you can publish and invite others without the original designer. If any item is missing, the exit is not clean.
CTA
Own the accounts before you fall in love with the design.
Explore /websites or book a Website sprint at /contact?intent=websites-sprint.
What questions does this article answer?
- Who owns the code after launch?
- Only what the agreement says — plus what you can actually access. Prefer assignment or a clear license *and* a repo or project transfer into your account. Paper ownership without a login is incomplete. This is not legal advice; have counsel read the IP clause for your jurisdiction.
- Can an agency keep my domain?
- They can if they are the registrant. Do not allow that pattern. Be the registrant from day one, or start the transfer immediately after purchase with an auth code you control, and remember ICANN’s 60-day lock after registration or a prior transfer.
- What if hosting is on their credit card?
- Move billing and project ownership before launch week ends. Netlify, Vercel, Webflow, and Framer all have transfer flows — they require *you* to accept into a team or Workspace you own. A site that dies when their card fails was never yours in practice.
- Do I need Git access?
- For code sites, yes — or org membership that lets a future team take over. For Webflow or Framer, you need project ownership transfer and clarity on exports instead. A ZIP of the live files is a souvenir, not a source of truth.
- What about Google Analytics and Search Console?
- Both should live under a Google account your company controls, with the studio as an optional collaborator. Otherwise your history and verification leave with them. Use a Search Console Domain property verified by DNS TXT you control.
- What is a clean exit checklist?
- Domain, DNS, hosting, code or project, CMS seats, forms, fonts and licenses, GA4, Search Console, and proof you can publish and invite others without the original designer. If any item is missing, the exit is not clean.
- icann.org
- icann.org
- developers.cloudflare.com
- developers.cloudflare.com
- docs.netlify.com
- docs.netlify.com
- vercel.com
- help.webflow.com
- copyright.gov
- docs.github.com
- docs.github.com
- docs.github.com
- help.webflow.com
- framer.com
- docs.netlify.com
- support.google.com
- support.google.com
- support.google.com
- lookup.icann.org
Last reviewed
Websites
Websites Linktree is a leak — build the house
Spotify does not send you the fan’s email. Instagram rents the following. Linktree is a hallway with no register. The House is the owned room: site, membership, checkout, follow-up.
Websites The shop site that answers the phone
A Midwest shop does not lose the job to a prettier hero. It loses the job to whoever looks real and picks up. Here is what the site has to do on a Saturday.
Websites A media kit the brand can steal in sixty seconds
Influencers need a brand-safe /media or /kit with rates and demographics you can stand behind — not a Google Doc with dead links. This is not a booker EPK.
Websites Creator Site or Business Site for the house?
Creator Site ($3,500) is tour, listen, join, buy. Business Site ($8,000) is the register. Pick after the $1,500 sprint — not before you have seen the house.
Will's Journal in your inbox.
What I learned this week building for shops, floors, and houses.
You're on the list.
Sign-up failed — try again.
By subscribing, you agree to the Privacy Policy.