ESTA Frequently Asked Questions (FAQs)

  • What is the EastWest System Tech Assistant (ESTA)?
    • ESTA is EastWest’s electronic AI available on Facebook Messenger. It allows you to view information, make requests, and perform transactions related to your EastWest credit card account(s).

      ESTA has been approved for use by the Bangko Sentral ng Pilipinas (BSP), and Facebook Messenger is only the user interface. We do not store your credit card number or any other sensitive information that can be used to complete a transaction.

  • Is using FB Messenger safe?
    • The user interface carries the native security features of FB Messenger. Access is protected by

      1. username/password validation,
      2. 2-Factor authentication, when enabled,
      3. Device ID binding, and
      4. Geographic anomaly detection.

      Your mobile number is already registered with your Facebook account. As such, there is no incremental information risk.

      As long as the device you use is protected with a passcode, there is nothing to worry about.

  • How do I know that I have been invited by the legitimate EastWest entity to register?
    • The invitation should have originated from a mobile business account with the Identity EASTWEST. Mobile telephone companies only allow the legitimate owner of this business name to use it. If you have previously used the EastWest portal or mobile app, you would have received SMS one-time passwords from the same mobile business account.

      We also do not ask you to disclose information that can be used by fraudsters to compromise your account. We send the OTP to your mobile number on record. We then ask you to key in only the last 4 digits of your EastWest credit card.

      The last 4 digits of your credit card account are also useless to fraudsters, but we can use it to authenticate your identity.

  • What can I do with ESTA?
    • With ESTA, you can do the following:

      • View real-time credit card balances
      • Protect your credit card account from online fraud with real-time locking and unlocking feature
      • View current and past statements of account
      • Convert transactions to installments
      • Request for credit card limit increases
      • Report lost card
      • Report declined transactions
      • Dispute unauthorized transactions
      • Request for supplementary credit cards
      • Enroll in electronic Statement of Account (e-SOA)
      • Update contact info
      • View ongoing and upcoming promos
      • Send feedback to our Customer Service representatives

      *Watch out for our updates as we are continuously working on new product features.

  • Is ESTA available 24/7?
    • Yes, you may access ESTA 24 hours a day, 7 days a week.

  • Who may sign up for ESTA?
    • ESTA is open to all EastWest customers with existing EastWest credit card(s).

  • How do I sign up for ESTA?
    • You shall receive an e-mail, SMS, and Viber notification if you are an existing EastWest credit cardholder. You may also launch m.me/EWBESTA in your web browser or simply type @EWBESTA in the search bar of your Facebook Messenger.

  • How long does it take to register?
    • Registering should not take longer than a few minutes. We’ve designed the process to be as user- friendly as possible without compromising the security of your account.

  • Will using ESTA consume my data plan?
    • if your mobile provider offers free FB data, then interactions with the BOT will not consume your data plan.

  • Howdo Facebook Messenger and EastWest ensure that my account is protected?
    • Make sure that your device is protected with a passcode before you log into Facebook Messenger.

      When you are attempting to log into your Messenger account from a new device, Facebook will prompt you to authenticate your identity again and will notify you of any suspicious log-in attempts.

      Your messages flow from your Messenger account to Facebook servers to our Facebook Business Messenger account and finally to our back-end Artificial Entity, which is outside of the Facebook electronic infrastructure.

      The information transmission between Facebook and EastWest is secured using Secure Sockets Layer encryption technology. Should the transmission be intercepted, it will be unintelligible and useless without a decryption key that is known only to Facebook and EastWest.

      We also ensure that we respond only to requests that originate from the legitimate Facebook server by whitelisting its IP address. Information requests from other IP addresses will be rejected.

      We identify information requests from you using a tag called the Facebook Page Scoped ID (PSID). When you first initiate a Messenger interaction with the EastWest Cards Facebook Messenger account, Facebook generates a PSID for you. This PSID is unique to you and unique to your interactions with EastWest. It will not work for your interactions with other business entities. At the same time, your PSID with other entities will be alien to us.

      Once this PSID has been created, Facebook will send it as part of the payload of all your messages to EastWest. This is how we identify you.

      All our responses also carry the PSID so that Facebook knows who to send it back to.

      As such, there is no risk that we will mistakenly provide information to the wrong party.