What you actually own when the project ends

Three years after launch you decide to move. Maybe the studio stopped answering. Maybe you outgrew each other. Maybe the one person who knew your site left and nobody replaced them. You send a polite email asking for the logins and the domain, and what comes back is silence, an invoice, or a sentence that starts with “unfortunately the licence is under our account”.
That is the moment ownership stops being a paperwork question and becomes a commercial one. Almost nobody asks about it at the start, because at the start everyone is getting along and the conversation is about the homepage.
Website ownership is not one asset, it is a list
There is no single deed to a website. There is a domain name, a hosting account, a CMS login, a set of plugin and theme licences, design source files, font licences, image licences, and analytics history. Each of those is held separately, each can end up in a different name, and each fails in a different way when the relationship ends.
The failures are rarely dramatic. Nobody takes your site down. What happens is quieter. Renewals stop, updates stop, and a year and a half later you have a website that still works but cannot be changed, sitting on a domain you are not a party to.
Here is the list, roughly in the order it hurts.
The domain name is the one that actually hurts
Everything else can be rebuilt. The domain cannot, because somebody else holds it and you are asking them nicely.
Two roles matter and they are not the same thing. The registrant is the holder of the registration. The administrative contact is an operational role attached to it. Agencies frequently occupy one or both, sometimes because the client asked them to handle it, more often because it was quicker on the day and nobody wrote down what had happened.
ICANN’s own guidance for registrants deals with this case directly. If the registrar or the agency is listed as the administrative contact and that is holding up a transfer, you can ask your new registrar to send the authorisation form to you instead, but only if you are listed as the registrant. If the agency is the registrant, that route is closed.
There is also a trap waiting for anyone who tries to fix this in the obvious order. Under ICANN’s transfer rules, changing the registrant name, organisation or email address triggers a 60-day lock that prevents the name moving to a different registrar. So the instinct, put the domain into our name first and then move it somewhere we control, is exactly backwards. ICANN’s advice is to request the registrar transfer first and change the registrant afterwards. Do it the other way round and the name sits where it is for 60 days while you wait the lock out.
Singapore names have their own mechanics. For .sg and .com.sg, SGNIC requires the registrant to obtain a domain transfer password from the current registrar before the gaining registrar can submit a transfer request, and the losing registrar can approve it, reject it, or ignore it, in which case SGNIC lets it through after seven days. That password comes out of the registrant’s relationship with the registrar. If the relationship is the agency’s, so is the password.
Check your own WHOIS record this week. It takes a minute and it is the single highest-value thing in this article.
Who owns the hosting account?
One question settles it. If you rang the hosting company today and gave them your company name, would they have any idea who you were?
A lot of small-studio hosting is resold. The studio holds one account with a host and puts client sites inside it. That is not automatically a bad arrangement, and for a small site it is often cheaper and better managed than the alternative. But you do not have a hosting account in that model. You have a folder inside somebody else’s, your billing relationship is with the studio rather than the host, and if the studio’s account lapses for any reason, yours goes with it and no warning email reaches you, because the renewal notices are not addressed to you.
What you want instead is boring: the hosting account in your company’s name, billed to you, with a login you can use without asking permission, and a copy of the backups somewhere you control. If a studio manages it on your behalf, that is a service arrangement sitting on top of an account that is still yours.
We host from S$200 a year, and what moves that number is traffic, whether the site needs a staging environment, and how much email sits alongside it. The account is registered to the client either way. Hosting is a service we provide, not a hostage we hold.
The CMS login, and the licences underneath it
Administrator, not editor. Your own named account, not a shared one that four people know the password to.
Then there are the licences, which is where most of the surprises live. WordPress, and anything derived from it, is released under the GPL, and the WordPress project’s stated position is that plugins and themes inherit that licence. In practice this means the code sitting on your server stays with you. Nobody can repossess it.
What is not covered by that is the licence key. A commercial plugin or theme subscription is a service contract. It buys updates, support and library access, and it is tied to an account. Elementor’s terms are unusually plain about it: you may not let others use your account or licence by sale, lease, assignment or transfer, you may not use an activation code on more sites than you paid for or it gets blocked, and software you received under the GPL stays with you under that licence.
Read those two together and you get the real outcome of a badly handled handover. Your site keeps running. It stops receiving updates. And a site that stops receiving updates does not fail on a Tuesday. It degrades quietly for a couple of years and then gets compromised.
We see the end state of that regularly. Across 54 Singapore B2B sites we reviewed in August 2026, 12 were running an outdated or end-of-life CMS or plugin, including WordPress installs several major versions behind and a Joomla template that reached end of life in 2012. One firm was paying for platform maintenance that was reaching the software but not the site: the CMS underneath was current, and the front end had not been touched in years.
The footer is the cheapest tell of the lot. Of the 23 sites in that review whose footer we examined, 19 carried an out-of-date copyright year, some as old as 2013. A copyright line that has stopped advancing is not a design fault. It is a maintenance fault with a visible symptom, and it usually means nobody who has access has opened the site in a long time. Where the same footer still credits the studio that built it, a visitor can date the last real involvement to the year.
Design files, fonts and images
Three things that are almost always handled worse than the technical assets, because they feel like they were part of the deliverable.
Source files. A PDF of a logo is not a logo. What you want is the vector master, horizontal and stacked lockups, full colour, single colour and reversed versions, and a short guide saying which goes where. For the site itself, the design source file with its components intact, not a flattened export. If a rebrand happens two years from now and the vectors are gone, you are paying someone to redraw your own mark.
Fonts. Web font licences are typically sold per domain or against a pageview band, and they are frequently bought in the name of whoever built the site. Ask whose name is on the licence and what happens at renewal. If the answer is vague, a well-chosen open licence typeface removes the problem permanently and costs nothing.
Images. A stock licence is granted to a named licensee, and it is not a file you can pass along with the JPEG. If the studio licensed the photograph, the licence sits with the studio. Either have it reissued in your name where the vendor permits that, keep the receipts, or plan to replace the pictures. It is one more argument for commissioning photography of your own equipment and your own people, which you own outright and which nobody else in your sector can use.
What a proper handover contains, and why to ask now
Short list. If it is not in the proposal, ask for it in writing before you sign, while you still have room to negotiate.
- The domain registered with your company as registrant, in an account you control, billed to you.
- Hosting in your company’s name, with a direct login to the host and a copy of the backups.
- A named administrator account on the CMS, created at the start of the project rather than the end.
- A written inventory of every theme and plugin: which are free, which carry a paid licence, whose account each one sits on, what it renews at, and what stops working if it lapses.
- Design sources: vector logo masters, lockups, the brand guide, and the site design file.
- Font and image licences in your name, or a written record of what was used and on what terms.
- Google Analytics and Search Console owned by your company account, with the studio added as a user rather than the reverse. Get this backwards and you lose your entire measurement history on the day you part company, which is the one item on this list that genuinely cannot be recovered.
- A named person to call, and the date the support window ends.
That list does not change with the size of the project. It is the same for a five-page site as it is for a build like Towa Marine, covering marine air-conditioning, ventilation and refrigeration work across Singapore, Port Klang and Tanjong Uncang, or THK Engineering, where five M&E disciplines had to be presented as a single package.
Every build we hand over includes 30 days of post-launch support afterwards, extended to 45 days on larger or more complex projects, covering bug fixes, minor content edits and questions. Maintenance after that starts from S$200 a month for security and plugin updates, backups, uptime monitoring and small layout changes. The point of a maintenance plan is that leaving it should cost you nothing but the maintenance. Our pricing is published rather than quoted on request, and so is what happens at the end.
The reason to raise all of this at the start is that the leverage is all at the front.
At the start of a project, ownership is an administrative paragraph that any reasonable studio will agree to without blinking. We put it in writing because it removes an argument neither party wants to have later, and because a studio that is uncomfortable with the list is telling you something useful for free.
At the end of a project, the same paragraph is a negotiation with someone who has no commercial reason to make it easy and, quite often, no clear memory of who set the account up. Nobody is being malicious. It is simply that a domain registered in a hurry in 2019 by a contractor who has since moved on is now a problem with no obvious owner, and you are the one holding it.
Ask the question while everyone is still getting along. It is the cheapest hour of the whole project.

