Give every release an identity
Use a semantic version such as 1.2.0 and an ISO date. Keep the previous release archive until the new delivery has been tested from a clean download.
Record hashes after every file is final. A renamed or re-exported file is a different artifact even when it looks identical.
Write for buyers, then for yourself
The buyer note should lead with the benefit and say whether they need to download again. Your internal change log can include production details, source versions, and checksums.
Preserve the original promise
Do not silently remove formats or features from an update. If compatibility changes, say so before replacing the live files and retain a path for customers who purchased the earlier promise.