Record the source, not just the file name
Keep the exact product name, marketplace/vendor, seller or publisher, listing URL, listing/product ID when available, and the date you obtained it. A folder named “castle_pack_final” is not enough context when the source page changes later.
Index purchase evidence
Record the amount/currency and an order or receipt reference. Keep the receipt itself in your normal project/admin records. Do not copy passwords, full payment-card credentials, CVV/PIN data or OTPs into a tracker.
Keep the official license reference
Write the license name exactly as the source presents it and keep the official URL or saved-file reference. If attribution or redistribution is unclear, record “Unknown” and review it before release or source-file handoff instead of guessing.
Map the asset to projects
Record where the asset is actually used, whether it was modified, and where any required credit lives. This turns a purchase list into a useful production record.
Set a manual re-check date
Long-lived projects benefit from a deliberate review date, especially if marketplace terms, project use, or handoff requirements change.
This is recordkeeping guidance, not legal advice. Whether a license permits a specific use must be verified from the current official terms or qualified advice.