Yes using HTTPS, the end-to-end security is really good, but that does not mean your data is 100% secure. At application layer (in your ase Facebook) the data is still accessible for third parties, it's just a matter of time until someone finds a vulnerability and exploit it.
As of your second question, your ISP can track your activities unless you're behind a proxy.