Correct.
Your ISP can see:
That you use Tor. Your first hop connects to a guard relay, and all relay IPs are on a public list. The traffic is fully encrypted, but "connected to known Tor relay" = "this customer uses Tor."
Volume and timing, how much, when.
Your ISP cannot see:
Content. Thanks to three layers of encryption, peeled one hop at a time. No single party holds both ends, by design.
Destination. The guard knows you but not where you're going. DNS also resolves inside the circuit, so no DNS leaks (unlike a sloppy VPN setup).