The Situation
You paid for a website. It works. Then one day you need to change a phone number, or renew a domain, or move to a new agency — and you discover you have no login for anything. The person who built it is not replying. The domain is registered in their name. The hosting is on their account. You do not have the code.
This is one of the most common and most avoidable problems in the Indian small business web market, and it is rarely malicious. Usually it is a freelancer who moved cities, changed careers, or simply stopped answering. The outcome is the same either way: a business asset you paid for that you cannot control.
Here is how to work out what you actually own, how to get it back, and how to make sure it never repeats.
Step 1: Separate the Four Assets
A website is not one thing. It is four separate assets with four separate owners, and you may control some and not others. Establish which is which before doing anything else.
| Asset | What it is | How to check who controls it |
|---|---|---|
| Domain name | Your address on the internet | Run a WHOIS lookup on your domain and read the registrant and admin contact |
| Hosting / server | Where the files live | Check your email for hosting welcome messages, or trace the site's IP to a provider |
| Code and content | The site itself | Do you have a copy? A repository invite? A database export? |
| Third-party accounts | Analytics, email, payments, CMS | Log in and check whether you hold the owner role or a delegated one |
The domain is the most important of the four by a wide margin. Whoever controls the domain can point it anywhere, and everything else can be rebuilt. Start there.
Step 2: Read Your WHOIS Record Carefully
A WHOIS lookup tells you which registrar the domain sits with, who is listed as registrant, the admin email address, and the expiry date. Privacy protection may mask the contact details, but the registrar and expiry are always visible.
Three outcomes are possible:
- You are the registrant and the admin email is yours. Best case. Do a registrar password reset and you have control today.
- You are the registrant but the admin email belongs to the developer. Recoverable. Contact the registrar with proof of identity and business ownership and request a change of contact email.
- The developer or their company is the registrant. Hardest case. This is a transfer or a dispute, covered below.
Note the expiry date regardless of which case applies. If the domain lapses while you are sorting this out, it can be picked up by anyone after the redemption window, and reacquiring it becomes an expensive negotiation rather than a legal question.
Step 3: Make a Clean Written Request First
Before escalating anything, send one clear, unemotional written request — email, not WhatsApp voice notes — asking for a specific list of items with a reasonable deadline. Keep it factual and businesslike. A surprising proportion of these situations resolve at this step, because the developer was avoiding a conversation they assumed would be hostile.
Ask specifically for:
- Registrar account access or an authorisation code to transfer the domain
- Hosting control panel credentials, or a full backup of files and database
- CMS or admin account with owner-level permissions
- Owner access on analytics, search console, and any business email accounts
- Written confirmation that the work delivered is yours to use and modify
Keep every reply. If this ends up in a dispute, a documented paper trail of a polite request and no response is materially useful.
Step 4: Escalation Routes That Actually Work
If the domain is registered to them
Contact the registrar directly with your payment records, business registration, and correspondence. Registrars deal with this regularly and many have an internal process for it. If the domain matches a name you hold a trademark on, you have a stronger route: INDRP for .in domains and UDRP for .com and other gTLDs are arbitration processes designed for exactly this kind of dispute, and they are considerably faster than court.
If the hosting is on their account
The hosting provider will generally not hand over an account belonging to someone else, but they will often help you retrieve your own data if you can prove the content is yours. Failing that, remember that hosting is the most replaceable of the four assets — you can stand up new hosting in an hour.
If they are holding the site to ransom
Demanding payment beyond the agreed scope to release assets you have already paid for is a contractual matter, and a legal notice from a lawyer costs a few thousand rupees and resolves a large share of these cases immediately. Weigh that against simply rebuilding, which is sometimes cheaper and always faster.
Step 5: Know When To Stop Fighting and Rebuild
There is a point where recovery costs more than replacement. If the site is a five-page brochure built on a template, a dispute lasting three months to recover it is a poor trade — a new site can be built in two to four weeks and will almost certainly be better.
Rebuild rather than recover when the site is small, the code has no unusual custom functionality, and your content still exists somewhere you can reach it. Fight for recovery when there is genuine accumulated value at stake: years of blog content and its search rankings, an e-commerce order and customer history, a membership base, or integrations that would be expensive to rebuild.
One thing worth knowing: even if you lose the files entirely, much of your published content can be retrieved from the Internet Archive and from Google's cache. It is tedious but it is not nothing.
How To Structure the Next Project So This Cannot Recur
This entire category of problem is prevented by about an hour of setup at the start of a project.
- Buy the domain yourself. Your own registrar account, your own credit card, your own email address as registrant. Add your developer as a delegated user if the registrar supports it. This single habit prevents most of the pain described above.
- Own the hosting account. Same principle. Most modern hosts support team members with scoped permissions — that is what your developer should have.
- Insist on IP assignment in writing. One clause stating that all deliverables and their intellectual property transfer to you on final payment. Without it, the default position under Indian copyright law may leave the code with its author.
- Require a handover package. Source code, database export, asset files, credentials list, and a short document explaining how the thing works. Make it a deliverable tied to final payment rather than a favour asked afterwards.
- Hold owner role on every third-party account. Analytics, Search Console, payment gateway, business email, CMS. Grant your agency admin access; keep ownership.
- Take your own backups. Monthly, stored somewhere your developer cannot reach. This alone converts a crisis into an inconvenience.
None of this reflects distrust. It reflects the reality that professional relationships end, people move on, and a business asset should not depend on any individual remaining reachable. Our guide to choosing a web design agency in India covers what else to check before signing.
The Questions To Ask Before You Hire Anyone
- Will the domain be registered in my name, on my own registrar account?
- Will I hold the hosting account, with your team added as users?
- Does the contract assign intellectual property in the deliverables to me?
- What exactly is included in the handover package at the end?
- If we part ways, what does your offboarding process look like?
Any competent studio answers all five without hesitation, because they have answered them before. Hesitation on question one or three is a reason to keep looking.
At Kalex Studio, every project ships with client-owned infrastructure and a full handover package as standard — you own the domain, the hosting, and the code from the first day. If you are currently locked out of your own site and want a straight assessment of whether to recover or rebuild, tell us the situation and we will tell you honestly which is cheaper.