Your developer owns your domain. Here is how to find out, and get it back.
You paid for the website. You have been paying monthly since. And when you asked for the login to your own domain, the answer was slow, then vague, then nothing at all.
This happens more often than most merchants realise, and it is usually more recoverable than it feels on the day you discover it. Here is how to find out exactly what you own, in the right order, before you pay anybody to fix it.
First, separate four things that are not the same
People say "my website" and mean one thing. It is really four, held in four different places, and you can own some and not others.
- The domain. Held at a registrar such as Namecheap, GoDaddy or Cloudflare. Whoever controls the registrar account controls where the domain points, and can move it or let it expire.
- The hosting. The server the site runs on. Separate account, separate bill, often a different company entirely.
- The store admin. Your login to the site itself. There is a real difference between an administrator and a limited user who can edit product descriptions.
- The merchant account. The processor that takes the card payments and decides which bank account the money lands in.
A developer can hand over number three, which feels like a handover, while keeping one, two and four. That is the situation worth checking for.
Check the domain yourself, right now
This takes two minutes and costs nothing.
Look up your domain on a public WHOIS service such as ICANN Lookup. You are looking for two things: the registrar (which company the domain is registered through) and the registrant or admin contact.
Most domains now show redacted contact details for privacy, so you may not see a name. That is normal and it is not evidence of anything. What you can always see is the registrar and the expiry date. Write both down.
Then ask yourself the question that actually settles it: have you ever logged into that registrar? Not the website editor. The registrar. If you have never had an account there, and renewal notices have never arrived in your inbox, the domain is not in your control regardless of whose name is on it.
The rest of the checklist
Go through these honestly. Any one of them on its own is fixable. Several together mean the business is running on somebody else's permission.
- Domain renewal notices go to an inbox that is not yours.
- You have never logged into the registrar or the host, only into the site.
- Your store login is not a full administrator.
- You cannot download a complete backup by yourself.
- The payment processor account is in the developer's business name.
- Cancelling the monthly fee would take the site offline.
That last one is the tell. If stopping payment kills the site, you are not buying a service. You are renting your own business back.
What is usually recoverable
More than people expect, because registrars and hosts care about account records and billing, not about who wrote the code.
If the account is in your name and you have lost access, the provider's own account-recovery process is designed for exactly this. Billing records, the card the renewals were charged to, and email access are the evidence that tends to matter.
If the domain is registered to a company you paid, you can request a transfer. A domain transfer needs the authorisation code from the current registrar and the domain must be unlocked. A cooperative developer sends both. An uncooperative one does not, and there is no button that overrides them.
If the developer has simply gone quiet, that is the common case and it is usually workable. Silence is not the same as refusal, and providers respond to account holders rather than to whoever shouts loudest.
What is not recoverable, and when to stop trying
If a domain is registered in someone else's name and they actively refuse to release it, no agency can force it. What exists is the registrar's dispute process, and beyond that a lawyer. Both are slow and neither is certain.
There is a decision hiding here that people avoid for months: at some point a new domain is cheaper than the fight. A domain costs about the price of a coffee run per year. Weeks of dispute cost you every sale you did not make while your store was down. If the products are the business and the domain is six months old with no meaningful search ranking attached to it, start again on a new one and pursue the old one in parallel if you still want to.
That advice is different if the domain is ten years old and carries every link and ranking you have. Then it is worth fighting for. The honest version of this conversation depends on which of those you are, and anyone who gives you the same answer either way is not looking at your situation.
Two things to do before you hire anyone
Get your data out. Export your product catalogue, your customer list and your order history today, from whatever access you do have. If access is later cut off, this is the difference between a migration and a rebuild from screenshots.
Change the email on anything you control. Password resets flow through email. If your recovery address is still an account somebody else can read, fixing that comes before everything else.
Then, and only then, work out what a rebuild is worth. We start every migration with an audit that tells you which of those four things are actually in your name, and we tell you the answer whether or not it leads to work for us. Send us your site and what you can and cannot log into.