Skip to content

Who Owns Your Website, Your Data, and Your Automations

Every piece of your setup is owned, rented or borrowed. None of those is wrong. Not knowing which is which is what turns an ordinary Tuesday into a bad month.

Article banner listing five parts of a website setup with an ownership badge beside each: Domain Name rented, Website and Content owned, Plugins borrowed, CRM Records owned with a question mark, Integrations owned.

At some point the website stopped being a website. There is a domain, a WordPress installation, a handful of plugins, a CRM, a form that writes into it, an embedded booking widget, and two automations that somebody set up on a Thursday afternoon and never wrote down.

That is a system, and it is yours in the sense that you are responsible for it. Whether it is yours in the sense that you could take it somewhere else is a different question, and it is the one nobody asks until the day it matters.

Owned, rented, borrowed#

Three states, and each piece of your setup is in exactly one of them. Owned means you hold it and could move it elsewhere. Rented means it works for as long as you keep paying. Borrowed means it works for as long as somebody else keeps choosing to maintain it, and you are not the one making that choice.

The pieceUsuallyWhat happens if it goes away
Your domain nameRented, and renewedEverything stops at once. Email included
Your website content and structureOwned, if it is a real WordPress installationNothing, provided you can get an export out
PluginsBorrowedThe site keeps running. The feature stops being maintained
An embedded hosted serviceRentedThe block goes blank and the page keeps loading around it
Your CRM recordsDepends entirely on the export buttonThis is the one that ends businesses
A ready-made connector between two toolsBorrowedThe chain breaks quietly, which is worse than loudly
An integration built for youOwnedNothing, if somebody can still read the code

None of these states is bad. Renting is usually the right call and borrowing is how anyone ships anything. The damage comes from believing a rented thing is owned, which is a belief that only gets corrected at the worst possible moment.

The domain is the only irreplaceable one#

A website can be rebuilt in an afternoon now. Content can be rewritten. A CRM can be repopulated from invoices if it comes to that. The address cannot be re-earned, because it is sitting in your customers' bookmarks, on your van, in the signature of every email your company has ever sent, and in the part of a search engine's memory that took years to build.

So the domain gets treated differently from everything else on the list. It is registered to the business, in an account the business controls, with a card that will not expire quietly, and with the renewal notices going to an address more than one person reads.

The most common version of this failure

The domain sits in the personal account of whoever built the first version of the site, years ago. Nobody notices, because it renews. Then they change email address, or stop replying, or the card on the account expires, and the business discovers that the single thing it cannot replace was never in its name. Go and check whose account your domain is in. It takes two minutes and it is the highest-value two minutes in this article.

Your website content#

This is where the difference between a real installation and a platform account decides everything. If your site is an ordinary WordPress installation, then the pages, the posts, the media and the settings are in WordPress's own formats, which every WordPress developer and every host already knows how to read. Getting them out is a normal operation rather than a negotiation.

One precise thing, because it is the kind of assumption that only surfaces when someone is in a hurry. On Sitebefy there are two different exports and they contain different things. The data export in your account settings covers the personal data held about your account, which is a data-protection right and a button. It does not contain your website. Your website content comes out of WordPress's own export, or out of a backup.

Two exports, two different jobs

Account data export: what the company knows about you as a customer. Website export or backup: your pages, posts, media and settings. People reach for the first when they mean the second, usually on the day they are leaving, which is the worst day to discover the distinction.

The data your business actually runs on#

Your website can be rebuilt. Ten years of customer history cannot. The CRM, the form submissions, the quotes and the notes are the part of this system that is genuinely irreplaceable, and they are also the part most likely to be sitting inside a product you rent.

Ask the export question before you put the first record in, not after you have put in ten thousand. And ask it in a specific form, because vendors answer the vague version generously.

Can I get every record out, with its history and its attachments, as a file, today, without opening a support ticket? Go and do it once, now, while nothing is wrong. An export you have never run is a claim on a marketing page. An export sitting in a folder on your machine is a fact.

Plugins are borrowed, and that is usually fine#

An abandoned plugin does not vanish. Your site keeps running exactly as it did yesterday, which is what makes this a slow problem rather than a sudden one. What stops is maintenance: no fixes when WordPress or PHP moves on, and no patches when somebody finds a hole in it.

So the question to ask before depending on one is not whether it is popular. It is what you would do if it stopped being updated tomorrow. For a gallery, you would swap it in an afternoon and barely notice. For the thing that holds your bookings or takes your payments, the answer is longer, and that difference is the whole of the risk assessment. Which of the four routes a feature should arrive by is worked through in the guide on adding business features.

What happens when a person leaves#

Vendors disappearing is the risk people plan for. People leaving is the risk that actually bites, because a departing person takes the map with them and the map was never written down.

  • Accounts in an individual's name rather than the company's, especially the registrar and anything holding a payment method.
  • Credentials that live in one person's password manager and nowhere else.
  • An integration somebody wrote that works perfectly and has no documentation, so nobody dares touch it.
  • An automation nobody else knows exists, quietly doing something important, until the account it runs under is deactivated.
The handover page

One page, kept wherever your company keeps things that outlive people. For every account and service: what it is, whose name it is in, who else can get in, what it costs, and what stops working if it lapses. It takes an hour to write and it is the single cheapest piece of continuity insurance a small business can buy. Update it the day anything changes, not on the day somebody resigns.

Backups are not an archive#

Two things about backups surprise people at the point of use, and both are worth knowing before then rather than during.

A restore is not a merge. It puts the site back to that moment, which also means discarding everything done since. If you are restoring because of something that happened this morning, you are also giving up this morning's other work, so take a fresh backup before you restore and you keep the option of coming back.

Backups live with the site, not beside it

Deleting a site removes its content, its backups and its history together, and it is not reversible. A backup does not survive the thing it was taken from. So download whatever you want to keep before you delete anything, and treat the download as the archive. On Sitebefy the subdomain is then held for ten days before anyone can claim it, which protects the address from a stranger but does not bring the site back.

The drill nobody runs#

The useful question is not whether you have backups. It is whether you have ever restored one. Backups fail quietly in exactly the way automations do, and the moment you find out is the moment you needed them.

  1. Take a backup today, so there is a known-good point to come back to.
  2. Export your CRM records and open the file. Not the download, the file. Check the columns you would actually miss are in it.
  3. Look up who your domain is registered to, in the registrar rather than from memory.
  4. Write the handover page. An hour, once, and revised whenever something changes.

When something does break, the first useful question is when it started, and that is usually easier to answer than people expect. Sitebefy keeps an activity feed of builds, regenerations, restores and setting changes, so if the site broke on Thursday you can see what happened on Thursday. Most causes are found that way rather than by investigation.

What leaving well looks like#

You should be able to describe your exit without anyone's permission. The domain moves because the account is yours. The site moves because a WordPress export and a backup are things any host can take. The records move because you tested the export while you were still happy. The custom work moves because it is code sitting on your installation rather than a feature of somebody's platform.

That is the practical meaning of the difference between a real installation and a closed builder, and it is worth understanding before it is worth acting on, because it costs nothing on the day you launch and everything two years later. The two routes are compared here.

The costs guide puts one of these questions in front of a developer's quote: what happens to this if I leave. It is the same question asked earlier, and it is worth asking about every line of your setup, not only the custom-built part.

The one-page audit#

Five columns, one row per piece of your setup. It fits on a page for almost every small business, and the act of filling it in finds the problems more reliably than reading about them does.

ColumnWhat goes in it
The pieceDomain, site, each plugin that matters, CRM, each integration
Owned, rented or borrowedOne word, and be honest about the difference
Whose accountA company account, or a person's name, which is the answer that needs fixing
What breaks without itOne sentence, in terms of what a customer would notice
How the data comes outThe actual steps, and the date you last did it

The last column is the one that does the work. Everything above it can be filled in from memory, and memory is where the comfortable answers live.

Start on a site you can take with you

Describe what you do and Sitebefy builds a real WordPress site you own, with the pages, layouts, content and SEO already in place. You hold the WordPress credentials, the content is in WordPress's own formats, and backups are yours to download, so nothing here depends on staying. Look at the result before creating an account, and every plan carries a 14-day money-back guarantee.

Build my site

Why this is worth an hour#

Nothing in this article makes your website better. No customer will ever notice that your domain is in the company's name or that you have opened your CRM export once. It is unglamorous work with no visible output, which is exactly why it stays undone until it is urgent, and by the time it is urgent it is no longer an hour's work.

The businesses that survive a bad week are not the ones with better tools. They are the ones who could answer, before the bad week, where everything was and how to get it back.

Share
Sitebefy

Senior editor

Senior Editor with a passion for crisp prose, sharp arguments, and flawless execution.

Comments · 0 comments

Log in to join the conversation. Log in

One useful email, twice a month

No spam. Unsubscribe anytime.

Your first draft
is one form away

Pick a template, answer a few questions about your business, and read what the AI wrote before you pay anything.

See pricing