Lock-in doesn’t come from a contract — it comes from four accounts, and if you hold all four you cannot be held hostage regardless of what anyone else does. Set them up in your name from day one and the whole fear disappears for about ₹1,000 a year.
What lock-in actually is
Not a legal trap. An access problem.
Complaint records show what it looks like in practice: buyers unable to move a website because the domain sits in a developer’s account, and in at least one case a live site taken offline during a payment dispute. In neither situation was there a contract binding the buyer. There was simply nobody else who could act.
Control follows the account, not the payment. That’s the whole mechanism.
The four accounts
| Account | What it controls | Who should hold it |
|---|---|---|
| Domain registrar | Your business name online; where renewal notices go | You |
| Hosting | Where the site lives; the files | You |
| Site admin (e.g. WordPress) | Editing content | You, plus the developer |
| Google / business email | Analytics, Business Profile, email on your domain | You |
Hold the first two and lock-in is structurally impossible. The third recovers through the second. The fourth matters because a Business Profile or payment gateway registered under someone else’s email creates its own dependency months later.
Setting them up correctly, day one
Fifteen minutes total, before you hire anyone:
- Create a registrar account with your own email. Buy the domain. Turn on auto-renew, check the saved card is current, put the expiry date in your calendar with a 30-day reminder.
- Buy hosting in your own name, on your own card. Note the expiry date too — it’s separate.
- Create the Google account and business email under your control, then use that address to register everything else.
- Give the developer access, not ownership. Registrars and hosts let you add a user or share DNS access without handing over the account. That’s the correct arrangement.
Point four is the one people don’t know exists. You don’t have to choose between doing it yourself and giving away control.
The one line to send any vendor
Will the domain be registered in my name, in an account I control, with my email address?
The answer must be an unqualified yes. Three deflections to notice:
- “We manage it for all our clients.” Means it goes in their account.
- “It’s technical, don’t worry about it.” Means the same.
- “It’s in your name, in our account.” The most misleading, because the registrant name and the account are different things — and the account is the one that decides what happens.
A vendor who resists this is protecting the leverage you’re trying to remove. That’s worth more than any price difference.
If you already don’t hold them
Recover in this order:
1. Domain. Run a WHOIS lookup and read the registrant email. Search your own inbox for a registrar welcome message — the account may already be yours and just need a password reset. If it’s genuinely theirs, request a transfer framed as routine housekeeping, not as a departure. Where that fails, registrars have ownership-claim processes and will weigh GST registration, invoices and payment records.
2. Hosting. Contact the hosting company directly as the account owner. Where the plan sits inside the developer’s reseller account, ask what recovery requires.
3. A backup. Once you have hosting, generate and download one. Keep your own copy off the server.
4. Admin access. Recoverable through hosting, without the developer.
Steps two to four collapse into one if you can reach the hosting account.
The message that usually works
Framing decides the outcome. Send this before there’s any dispute:
Hi [name]. For my records, could you confirm the domain registrar login, hosting login and site admin login? Also, please tell me whether anything — Google Business Profile, analytics, business email, payment gateway — is registered under your account for my business. Happy to settle anything pending.
No grievance, specific items, and the last question catches dependencies you didn’t know existed. If there’s a genuine unpaid balance, pay it — a few thousand rupees to end a hostage situation is the cheapest option available.
What to do this week
- Run a WHOIS lookup and read the registrant email.
- Search your inbox for a registrar welcome email and try a password reset.
- Contact your hosting company directly as the account owner.
- Download a backup and keep your own copy.
- Register the domain yourself before any future project.
If you want it done the certain way
Domain, hosting and email in your accounts, with your email — and we take access rather than ownership, which is how it should work with anyone. Both expiry dates and all three logins handed to you in writing at launch. WhatsApp us; we reply in about five minutes between 9am and 7pm.
Related reading
- Whose name is your domain registered in?
- Who really owns a domain?
- You don’t have a single password to your own website
- The friction of moving to a new developer
FAQ
How do I avoid being locked in by a web developer?
Hold four accounts in your own name: the domain registrar, hosting, site admin, and your Google or business email. Give the developer access to these rather than ownership of them — registrars and hosts both support that.
Can a developer refuse to release my website?
They can withhold cooperation, but if the domain and hosting are in your accounts they have nothing to withhold. Where they hold them, registrars and hosting companies have owner-recovery processes you can use directly.
What does “the domain is in your name, in our account” mean?
That the registrant record shows you but the developer holds the login. The account is what controls renewals, transfers and DNS, so this arrangement leaves practical control with them.