Ownership & Infrastructure
Who owns what when someone builds your website.
You should own every account your business depends on — the domain, the hosting, the CMS, the database, Stripe, Shopify, Analytics and Search Console. Your agency should hold administrator or developer access to those accounts, not ownership of them. That one sentence resolves most of the confusion, and almost every horror story you have heard about a business losing its website is a story about that sentence being ignored.
This page is the whole picture: what each piece of a website actually is, who should hold it, who pays for it, how a real project is sequenced, and what happens if you and your studio part ways. It is written for a business owner, not a developer. No prior knowledge is assumed and nothing is hidden to make the work sound harder than it is.
The principle, in four lines.
You own the accounts
Every account your business depends on — domain, hosting, CMS, database, payments, analytics — should be in your business’s name, on your email, with your recovery method.
We get access, not ownership
A studio needs administrator or developer access to build and run your site. It does not need to be the owner of anything to do that work well.
Nothing depends on one laptop
Your ability to reach your own infrastructure should never route through a StillAwake employee’s phone, email or password manager.
It is written down
Which accounts exist, who holds each one, what they cost, and what happens at the end — in writing, before the build starts.
The map
A website is five layers, not one thing.
When someone says “the website,” they are usually talking about one of five separate things that can each be owned, paid for and moved independently. Once you can see them separately, the ownership question stops being intimidating — it becomes five small questions with obvious answers.
01
The name
Your address on the internet, and the settings that point it at everything else — the site, your email, your verification records.
Sounds like
Domain name, DNS, registrar
Needed?
Always
02
The code
The actual files the website is made of, and the history of every change to them. This is the thing that gets rebuilt, moved or handed to someone else.
Sounds like
GitHub repository, version control
Needed?
Always for custom builds — replaced by the platform on Shopify, Framer or Webflow
03
The delivery
The machines that take that code and serve it to a visitor in Montréal or Melbourne in under a second, plus the certificate that makes the padlock appear.
Sounds like
Vercel, managed hosting, CDN, SSL
Needed?
Always
04
The content
Where the words and images live, and who can change them without a developer. A CMS is a convenience, not a requirement.
Sounds like
WordPress, Webflow, Framer, Sanity, Shopify content, custom admin
Needed?
Only if the content changes often enough that waiting on a developer is a real cost
05
The business systems
Anything that stores customer data, takes money, sends mail or measures behaviour. This layer is where ownership matters most, because it is where your customers and your revenue are.
Sounds like
Supabase, Postgres, authentication, Stripe, Shopify, Resend, GA4, Search Console
Needed?
Only what the business actually does — most brochure sites need none of it
Most small-business websites use layers one, two and three, and stop there. Layers four and five are added when the business genuinely needs them — which is a decision worth making deliberately, because each one adds cost, maintenance and a security obligation.
The matrix
Every account, who should hold it, and who pays.
This is the table to bring to a conversation with any supplier, not just us. Three rows are marked varies by contract — those are genuine commercial choices where more than one arrangement is honest. Everything else is a recommendation we would defend in any engagement.
Foundations
Domain name
- Recommended owner
- Client — registered to the legal business name, in a registrar account the client controls
- StillAwake’s role
- Technical contact when asked. We configure records; we do not hold the account
- Who usually pays
- Client, direct to the registrar (~$15–$60 CAD/year)
DNS / nameservers
- Recommended owner
- Client — it lives inside the registrar or hosting account they own
- StillAwake’s role
- Delegated access to create and change records
- Who usually pays
- Included with the domain or the host
Business email (Google Workspace, Microsoft 365)
- Recommended owner
- Client, without exception — it is the recovery method for everything else
- StillAwake’s role
- None, unless we are asked to set up DNS and deliverability records
- Who usually pays
- Client, per mailbox per month
Build
Source code repository (GitHub)
Varies by contract- Recommended owner
- Client owns the delivered code. The repository itself is usually transferred at handoff
- StillAwake’s role
- We build in it, and transfer or mirror it to the client organisation
- Who usually pays
- Nothing at this size — private repositories are free
Hosting / deployment (Vercel, managed hosting)
Varies by contract- Recommended owner
- Client account is the default. Hosting under our account is a valid managed-service choice — but say so in writing
- StillAwake’s role
- Deploy, monitor, configure domains and environment variables
- Who usually pays
- Client directly, or bundled into managed hosting / a care plan
CMS (WordPress, Webflow, Framer, Sanity, custom)
- Recommended owner
- Client — the owner seat on the account, and every piece of content in it
- StillAwake’s role
- Build it, configure it, train your team, keep an editor or developer seat
- Who usually pays
- Client, if the CMS is paid software. A CMS built into the site has no separate fee
Data
Database & backend (Supabase, Postgres)
- Recommended owner
- Client organisation — it holds your customers’ data, so it holds your legal obligations
- StillAwake’s role
- Developer access to build the schema, functions and security policies
- Who usually pays
- Client. Free tiers cover most projects at launch
Authentication & user accounts
- Recommended owner
- Client — it is part of the same backend project
- StillAwake’s role
- Implement sign-in, roles, permissions and session security
- Who usually pays
- Client, usually inside the backend plan
Money
Payments (Stripe)
- Recommended owner
- Client’s business entity. Not negotiable — the account is verified against your identity and pays out to your bank
- StillAwake’s role
- Restricted API access to build and test the integration
- Who usually pays
- Client — per-transaction fees, deducted from payouts
Ecommerce platform (Shopify)
- Recommended owner
- Client — store owner seat, products, inventory, orders and customer list
- StillAwake’s role
- Staff or Collaborator access, scoped to what the work needs
- Who usually pays
- Client — monthly subscription, apps, and transaction fees
Transactional email (Resend, Postmark)
Varies by contract- Recommended owner
- Client where the volume or the sender reputation matters. Ours is reasonable on a fully managed build — it should be stated either way
- StillAwake’s role
- Wire it into the site and set the SPF, DKIM and DMARC records
- Who usually pays
- Client. Free tiers usually cover contact-form volume
Measurement
Google Analytics 4
- Recommended owner
- Client’s Google account owns the property — years of history live in it
- StillAwake’s role
- Administrator or Editor role, granted by the client
- Who usually pays
- Free
Google Search Console
- Recommended owner
- Client — verify with a DNS record so verification survives a site rebuild
- StillAwake’s role
- Delegated Full user, for indexing, coverage and query data
- Who usually pays
- Free
Google Ads
- Recommended owner
- Client — the account, the billing profile and the conversion history
- StillAwake’s role
- Manager (MCC) access, so the account stays the client’s when management ends
- Who usually pays
- Client — ad spend billed to the client’s card, plus any management fee
Behaviour analytics (Microsoft Clarity)
- Recommended owner
- Client, or shared — it records sessions, so treat it as customer data
- StillAwake’s role
- Install and read it; recommend a consent gate before it loads
- Who usually pays
- Free
Google Business Profile
- Recommended owner
- Client — it is a verified record of a real business, and that business is yours
- StillAwake’s role
- Manager access to optimise listings, photos, posts and categories
- Who usually pays
- Free
Work product
Design files, brand assets, written content
- Recommended owner
- Client on final payment — including editable source files, not just exports
- StillAwake’s role
- We produce them and hand them over
- Who usually pays
- Included in the project fee
Where ownership can legitimately vary
Code can be assigned to you or licensed to you. Hosting can sit in your account or inside a managed plan. Transactional email can run on your provider or on ours. All six of those arrangements are used by reputable studios, and the choice usually comes down to whether you want to hold the platform or hold a single invoice. What is not a legitimate variation is leaving it undefined, or discovering the answer only when you try to leave. If a proposal does not name the arrangement, that is the question to ask before you sign — and our guide to auditing a website quote lists the other ten things a real quote specifies.
Plain English
What each of these things actually is.
Open the ones you need. Nothing here assumes you know what a nameserver is, and none of it is written to make the work sound more mysterious than it is.
Domains and DNSYour address, and the signpost that points at everything
A domain name is the address people type. You rent it from a registrar — Cloudflare, Namecheap, Google Domains, GoDaddy — for roughly $15–$60 CAD a year, and it is yours as long as you keep renewing it. DNS is the settings panel attached to it: a short list of records saying which server answers for the website, which service handles your email, and which records prove to Google or Microsoft that you control the domain.
Register it yourself, to your legal business name, on a company email address you will still have in five years. Turn on auto-renew and transfer lock. Then give your studio access to edit records — that is a five-second invitation and it is entirely reversible.
A lapsed domain is the one failure on this page with no clean recovery: an expired name can be bought by someone else within days, and it takes your email, your search rankings and every link anyone ever made to you with it.
Source code and repositoriesGitHub, and what handoff means
A custom website is a folder of files. Those files live in a repository — almost always on GitHub — which keeps the full history of every change, who made it and when, and lets any change be undone. The repository is also what the hosting platform watches: push a change, the site rebuilds itself.
Two things matter to you. First, that a repository exists at all — if a supplier is editing files directly on a live server, there is no history and no undo. Second, what your contract says happens to it: assigned to you on final payment and transferred to your GitHub organisation is the cleanest arrangement, and it is what we do. A licence is a legitimate alternative, but it should be a sentence you read, not a fact you discover.
Platform builds are different by nature. Shopify, Framer and Webflow sites do not produce portable code, and no honest supplier can promise otherwise — what transfers there is the account, not the codebase.
Hosting and deploymentVercel, CDNs, SSL, and where the site runs
Hosting is the machines that answer when someone visits your address. Modern platforms like Vercel do more than store files: they build the site from your repository, distribute it across a CDN — a network of servers worldwide, so a visitor in Melbourne is served from nearby — issue the SSL certificate that produces the padlock, and give you a private preview of every change before it goes live.
A small business site costs nothing to a few dollars a month at this tier. The account should be in your business name by default. Managed hosting under our account is the other honest model — one predictable invoice instead of four vendor logins — and if that is what you choose, the arrangement is written down and the site remains portable.
CMS — content managementWordPress, Webflow, Framer, Sanity, custom
A CMS is the admin screen where somebody changes words and pictures without touching code. The categories worth knowing: all-in-one platforms (WordPress, Webflow, Framer) where the CMS and the site are the same product; headless CMSs (Sanity, Contentful) which store content and hand it to a custom-built site; commerce content (Shopify pages and blogs, which come with the store); and a custom admin built into the site itself — which is what runs this website, and which is often the right answer when a business needs to edit six things rather than everything.
You do not automatically need one. A CMS earns its keep when content changes often enough that waiting on a developer is a real cost. Below that threshold it is an update obligation and an extra way to break the site.
Whichever you use, the owner seat belongs to you, and so does the content inside it.
Databases, authentication and storageSupabase, Postgres — and why most sites need none of it
Say this part plainly: a normal marketing website does not need a custom database. Pages, services, a portfolio and a contact form need no database at all. If a supplier proposes one for a five-page brochure site, the right question is what it would store.
You need one when the site holds something specific to each visitor: user accounts, bookings, saved data, memberships, an internal dashboard, a portal your staff logs into. In that case, Supabase is a hosted bundle of a PostgreSQL database (the industry-standard place to keep structured data), authentication (sign-up, login, password resets, roles) and storage (files and images uploaded by users) — the pieces a small team would otherwise have to run themselves.
Where it exists, it holds your customers’ data, which makes it your legal responsibility under Québec’s Law 25 and Canada’s PIPEDA regardless of who built it. That is the strongest reason the organisation should be in your name.
EcommerceShopify — products, inventory, checkout, orders, customers
An ecommerce platform is a database, a CMS, a payment flow and an operations tool sold as one subscription. Shopify holds your product catalogue, inventory counts, checkout, orders, shipping settings, discount codes and your customer list — which, over a few years, becomes one of the more valuable assets the business owns.
The store must be opened by you, under your business, with you as store owner. We work inside it with Staff or Collaborator access, which can be scoped to exactly the areas the work touches and revoked in a click. A supplier who insists on holding the owner seat is holding your customer list, and that should end the conversation.
If you are still deciding on a platform, our Shopify vs WooCommerce comparison covers the trade-off in detail.
PaymentsStripe — and why this one is never negotiable
Stripe is a payment processor: it takes card details on a page your site never sees, charges the card, and deposits the money in your bank account. Your site needs it only if you actually take money — a deposit, a subscription, a booking fee, a digital product, checkout on a custom store.
This is the one row on the matrix with no variation. A Stripe account is verified against a real legal identity, pays out to a real bank account, and carries the chargeback and tax obligations that come with taking money. It must be opened by your business, in your business’s name, on your banking details. We build the integration using restricted API keys you issue from your own dashboard, and you can revoke them without touching anything else.
EmailBusiness mail versus transactional mail — two different things
Business email — you@yourcompany.com, through Google Workspace or Microsoft 365 — is yours without qualification. It is the recovery address for every other account on this page, which makes it the single worst thing to have sitting inside somebody else’s tenancy.
Transactional email is different: the automated mail your website sends. A contact-form notification, an order confirmation, a password reset. Those go through a delivery service such as Resend or Postmark, because mail sent straight from a web server lands in spam. Free tiers usually cover a small business’s form volume entirely.
Whoever holds that account, the SPF, DKIM and DMARC records go in your DNS — they are what let receiving servers confirm the mail is genuinely from your domain, and they are the difference between arriving and being filtered.
Analytics and marketing accountsGA4, Search Console, Google Ads, Clarity
Google Analytics 4 measures what visitors do. Google Search Console shows what people searched before they arrived, and what Google thinks of your pages. Microsoft Clarity records sessions and heatmaps. Google Ads spends your money. Google Business Profile is your listing in Maps and the local pack.
All of them except Ads are free, and every one of them accumulates history that cannot be recreated later. They are also the accounts most often lost, because they are the easiest to create in a hurry under whichever Google login happened to be open. Create them under your business account, then invite your agency: Administrator in Analytics, a delegated Full user in Search Console, Manager access on Ads and on your Business Profile.
One technical detail worth insisting on: verify Search Console with a DNS record rather than an uploaded file or a tag in the page. File and tag verification break the moment the site is rebuilt. DNS verification survives it.
Right-sizing
You almost certainly do not need all of this.
Every service on this page costs money, attention and risk. The list of what a project needs should be an argument you win, not a stack you inherit. Here is the honest version.
A brochure or marketing site
Domain, code, hosting. That is the entire list. No database, no CMS unless you publish often, no Stripe, no Shopify. Most sites we build for service businesses stop here — and they are faster and cheaper to run for it.
A site with a blog or frequent updates
Add a CMS. Which one depends on who edits and how often, not on which platform is fashionable. If two people update three pages a quarter, a small custom admin beats a full platform.
A store
Add Shopify, or a custom store with Stripe. Shopify wins when you have inventory, shipping and a catalogue; a custom checkout wins when you sell a handful of things and want the site to stay one system.
A product, portal or booking system
Now you need a database, authentication and probably payments — the point at which a website becomes software, and where scoping properly matters most. Our guide to a custom web application covers what changes.
Working out which of those four you are is a requirements question rather than a technology one, and it has its own guide: what kind of website your business actually needs. Once that is settled, what to build it on — and which of these accounts you will end up owning as a result — is decided in the technology guide. If you would rather answer it by price, the project cost calculator asks about your business rather than about technology, and tells you which shape the project is — along with the range we would scope it from. Or read what separates a website from a web application.
The sequence
How a project actually runs, in order.
The order matters more than any single step. Ownership is established in step four — before anything is built — because every step after it inherits whatever was decided there. Fixing ownership after launch means migrating live infrastructure, which is work you pay for twice.
Before the build
Discovery
What the business does, who buys from it, what the site has to accomplish, and what already exists — including accounts nobody has logged into for two years.
Your part — Answers questions; digs up old logins
Architecture decision
Which of the five layers this project actually needs. A brochure site is decided here, and so is the difference between a $4,000 build and a $40,000 one.
Your part — Approves the stack in writing
Setup
Account provisioning
Each account is created once, on the client’s email, with the client’s multi-factor authentication. Doing it in this order costs twenty minutes; doing it later costs a migration.
Your part — Creates the accounts, keeps the recovery codes
Ownership established
Owner and billing seats sit with the business before a single line of code is written. This is the step that makes every later step reversible.
Your part — Holds owner and billing on every account
StillAwake access granted
We are invited as administrator, developer or collaborator — a separate account with separate credentials, scoped to the work. No shared passwords.
Your part — Invites us; can revoke in one click
Build
Design & development
Design direction, then the build itself, committed to a repository where every change is attributable and reversible.
Your part — Reviews; approves rounds
Integrations
Payments, forms, email, commerce, analytics and consent are connected using API keys issued from the client’s accounts — never keys borrowed from ours.
Your part — Issues keys; nothing to configure
Staging & testing
A private copy of the real site on real infrastructure. Payments run in test mode, email goes nowhere near a customer, and the whole thing gets checked on a phone.
Your part — Clicks through it; signs off
Live
Launch
DNS is pointed, certificates issue, redirects from the old URLs are in place, analytics and Search Console are verified, and the sitemap is submitted.
Your part — Approves the DNS change
Monitoring & maintenance
Uptime, backups, dependency updates, broken-form alerts and search performance. Either you watch this, or someone is paid to.
Your part — Chooses self-managed or a care plan
Handoff or ongoing management
A written inventory of every account, what it does, who owns it and what it costs — delivered whether you keep working with us or not.
Your part — Receives the inventory; owns everything in it
Security
Never share a password. Invite an account.
Emailing a login to a supplier feels like the fast option, and it creates four problems at once. Nobody can tell who made which change. You cannot remove one person without locking out everyone. Two-factor codes have to be relayed by text at the worst possible moment. And when the supplier changes staff, your credentials leave with someone you never met.
Owner account
Client
- Owner or admin seat on every account
- A company email address, not a personal one
- Their own multi-factor authentication
- Their own recovery codes, stored offline
- The billing method for anything they pay for
- The power to remove anyone, including us
Administrator / developer account
StillAwake Media
- A separate invited account, never a shared login
- Separate credentials on our own email domain
- Our own multi-factor authentication
- Permissions scoped to the work, not blanket ownership
- API keys issued from the client’s account
- Access that ends when the engagement ends
The test that matters
Your ability to reach your own infrastructure should not depend on a StillAwake employee’s laptop, phone, email address or authenticator app. If our entire team disappeared tomorrow, you would still be able to log into your domain, your hosting, your CMS, your database, Stripe, Shopify and your analytics — because they were always yours, and we were only ever invited guests inside them. That is not a promise about our conduct. It is a property of how the accounts were set up, and you can verify it yourself in ten minutes.
Offboarding
What happens if we stop working together.
Projects end. Budgets change, teams change, businesses get sold, and sometimes a working relationship simply runs its course. None of that should put your website at risk, and a studio that is confident in its work has no reason to make leaving difficult.
Nothing switches off
The domain, hosting, CMS, database, Stripe and analytics are already yours and already paid by you. Removing our access changes who can edit the site. It does not change whether the site runs.
You get the inventory
A written list of every account, what it does, which vendor it is with, who holds it and what it costs — plus the repository, the design source files, and any documentation written during the build.
Access is revoked, by you
You remove our administrator, developer, staff and collaborator accounts from your side. You do not have to wait for us to do it, and you do not have to trust that we did.
A new team can start immediately
Any competent developer can read a repository with a full commit history and pick up a standard stack. Nothing in the build depends on a proprietary tool only we can operate.
Search history survives
Because Analytics, Search Console and your Business Profile were verified under your accounts — Search Console by DNS record — the years of data behind them stay with the business rather than the supplier.
The door stays open
Support afterwards is available and priced publicly. Leaving is not penalised, and coming back does not require explaining a stack we cannot see, because we documented it on the way out.
If you are reading this because a previous supplier holds something of yours, that is a recoverable situation more often than it feels like. Domains can be transferred, Google properties can be re-verified by DNS, and a site can be rebuilt from what is publicly served even when the original files are gone. Start by finding out who your registrar is — everything else follows from that.
Managed service
Owning it and running it are two different jobs.
Owning your infrastructure does not mean administering it. Most business owners want the accounts in their name and the work off their desk, and those two things are entirely compatible — that is what a managed service is.
You keep
- The owner seat on every account
- The billing relationship for anything you pay for directly
- The data — customers, orders, submissions, analytics history
- The right to remove us, without notice or negotiation
We handle
- Deployments, uptime monitoring and daily backups
- Software, dependency and security updates
- DNS, SSL and deliverability records staying correct
- Small content edits, and fixes when something breaks
Our prices for that are published rather than quoted: managed hosting at $40 CAD per month, and a full website care plan — hosting, updates, monitoring, backups and small edits, with no separate incident fee when something breaks — at $150 CAD per month. Details are on the maintenance and support page, alongside one-time emergency pricing for sites we did not build.
Website ownership questions
Who owns the website when an agency builds it?
The client should own every account the business depends on: the domain, hosting, CMS, database, payment processing, analytics and Search Console. The agency should hold administrator or developer access to those accounts instead of owning them. Ownership of the design and code itself depends on the contract — assignment on final payment is the most common arrangement, and a licence is a legitimate alternative if it is stated in writing before the project starts.
Who should buy the domain name — me or my agency?
You should. Register it yourself, to your legal business name, in a registrar account you control, using a company email address you will still have in five years. Your agency can manage the DNS records and the renewals for you — that is a service. The registration itself should not be delegated, because a domain registered in someone else’s account is the single hardest thing to recover if the relationship ends badly.
Do I own my website’s source code?
Only if your agreement says so. In most custom builds the code is assigned to the client on final payment and the repository is transferred at handoff. Some studios license the code instead, and some platforms — Shopify, Framer, Webflow — do not produce portable code at all. None of these is dishonest. What is dishonest is leaving it unwritten. Ask the question before you sign, not after.
Who owns the Vercel or hosting account?
By default, the client. Hosting held under an agency account is a legitimate managed-service model — it is often how a fixed monthly hosting fee is delivered — but it must be disclosed, and the agreement must say what happens to the deployment if you leave. The test is simple: if the answer to “can I move this myself” is no, that should have been a decision, not a surprise.
What happens if I stop working with my web agency?
If the infrastructure was set up properly, almost nothing. You already own the domain, the hosting, the CMS, the database, Stripe and the analytics, so the site keeps running and you keep every login. You remove the agency’s access, receive the code and a written account inventory, and either bring in someone else or keep it as it is. If losing your agency means losing your website, the problem was never the departure — it was the setup.
Do I need to create all these accounts myself?
You create the ones your business depends on, and it takes about an hour in total — usually a domain, a hosting account, and whichever of Stripe, Shopify, Google Analytics or a database the project actually needs. We tell you exactly which ones, in what order, and sit on a call while you do it if that is easier. You never have to work out what a nameserver is; you only have to be the person holding the account.
Who pays for hosting, the domain and the other services?
The client pays the vendors directly, on the client’s card, for anything the business owns — typically $15–$60 CAD a year for a domain and free-to-modest monthly fees for hosting, a database and email at small-business volume. Analytics, Search Console and Google Business Profile are free. Alternatively, a managed plan bundles hosting and upkeep into one predictable monthly fee: StillAwake Media publishes managed hosting and a website care plan rather than quoting them privately.
What is a CMS, and do I need one?
A CMS — content management system — is the admin screen where someone changes the words and images on a site without touching code. WordPress, Webflow, Framer, Sanity and Shopify’s content tools are all CMSs, and a custom site can have a small one built in. You need one when content changes often enough that waiting on a developer becomes a real cost. A five-page site rewritten twice a year does not need one, and adding it anyway buys you an update obligation and a security surface for nothing.
Do I need WordPress?
No. WordPress is one CMS among several, and it is a reasonable choice for a content-heavy site with editors who already know it. It is not a requirement for having a website, it is not required for SEO, and it carries a real maintenance obligation: core, theme and plugin updates are the most common cause of a site breaking or being compromised. Choose it because the editing workflow suits your team, not because someone implied it is the default.
Does my website need a database?
Usually not. A marketing or brochure website — pages, services, a portfolio, a contact form — needs no custom database at all, and adding one adds cost, backups and a security obligation for no benefit. You need one when the site stores something specific to each visitor: user accounts, bookings, saved data, memberships, an internal dashboard. If a supplier proposes a database for a five-page site, ask what it stores.
What is Vercel?
Vercel is a hosting platform: it takes the code from a repository, builds it, and serves the finished site from servers around the world, handling SSL certificates and previews of every change along the way. For a business owner it is simply where the website runs — the modern equivalent of a web host. The account should be in your business’s name unless you have deliberately chosen a managed-hosting arrangement.
What is Supabase?
Supabase is a hosted backend: a PostgreSQL database, user authentication and file storage, packaged so a small team can run them without managing servers. A website only needs it if it stores per-user data — accounts, bookings, submissions, an internal tool. When a project does use it, the Supabase organisation should belong to the client, because it is the client’s customer data sitting inside it.
Why would my website need Stripe?
Only if you take money on the site — a deposit, a subscription, a booking fee, a digital product, or checkout on a custom store. Stripe is the payment processor: it handles the card details so your site never touches them, then pays out to your bank. The account must be opened by your business, in your business’s legal name, because it is verified against your identity and it is your bank account receiving the money. No agency should own a client’s Stripe account.
Who should own Google Analytics and Search Console?
Your business, on a Google account you control. Both are free, both accumulate history you cannot recreate, and both are routinely lost when an agency creates them under its own login. Grant your agency Administrator access in Analytics and delegate a Full user in Search Console. Verify Search Console with a DNS record rather than a file or a tag, so verification survives the next rebuild.
Should I share my passwords with my web agency?
No. Every platform worth using — Google, Shopify, Stripe, Vercel, GitHub, Supabase — lets you invite a separate user with its own credentials and its own multi-factor authentication. A shared login means you cannot tell who did what, you cannot revoke one person without locking out everyone, and your access depends on somebody else’s phone. Invite an account instead. It takes the same thirty seconds and it is reversible in one click.
What happens to everything after launch?
The accounts keep costing what they cost, the software keeps needing updates, and the search data keeps accumulating whether anyone reads it or not. Someone has to own that: either your team watches uptime, backups, updates and forms, or you buy a plan that does. What should not happen is the third option — nobody watching, which is how sites quietly break and stay broken for months.